{"grype_matches":[{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.10.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"risk":0.95628,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)"},"relatedVulnerabilities":[{"id":"CVE-2026-54513","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.10.0,<=2.18.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"risk":0.7792200000000001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation"},"relatedVulnerabilities":[{"id":"CVE-2026-54512","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"a9639a66d41d0232","cpes":["cpe:2.3:a:apache:sshd-common:2.9.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:sshd_common:2.9.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:sshd:2.9.2:*:*:*:*:*:*:*"],"name":"sshd-common","purl":"pkg:maven/org.apache.sshd/sshd-common@2.9.2","type":"java-archive","version":"2.9.2","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.sshd","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:org.apache.sshd:sshd-common","manifestName":"","pomArtifactID":"sshd-common","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.9.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjmq-gwgm-5qhm","versionConstraint":">=2.1.0,<2.9.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.sshd:sshd-common","version":"2.9.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mjmq-gwgm-5qhm","fix":{"state":"fixed","versions":["2.9.3"],"available":[{"date":"2023-12-08","kind":"first-observed","version":"2.9.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","metrics":{"baseScore":5,"impactScore":1.5,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-35887","cwe":"CWE-22","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-35887","cwe":"CWE-22","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-35887","date":"2026-10-08","epss":0.01311,"percentile":0.69795}],"risk":0.6555,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-35887","https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2","https://github.com/apache/mina-sshd/pull/362","https://github.com/apache/mina-sshd/commit/a61e93035f06bff8fc622ad94870fb773d48b9f0","https://issues.apache.org/jira/browse/SSHD-1324","https://github.com/apache/mina-sshd/commit/10de190e7d3f9189deb76b8d08c72334a1fe2df0","https://github.com/apache/mina-sshd/commit/c20739b43aab0f7bf2ccad982a6cb37b9d5a8a0b"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjmq-gwgm-5qhm","description":"Apache MINA SSHD information disclosure vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-35887","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","metrics":{"baseScore":5,"impactScore":1.5,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-35887","cwe":"CWE-22","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2023-35887","cwe":"CWE-22","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-35887","date":"2026-10-08","epss":0.01311,"percentile":0.69795}],"urls":["https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-35887","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.\n\nIn SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover \"exists/does not exist\" information about items outside the rooted tree via paths including parent navigation (\"..\") beyond the root, or involving symlinks.\n\nThis issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10"}]},{"artifact":{"id":"03cf6c677ea6f6c0","cpes":["cpe:2.3:a:apache:httpcore5-h2:5.3.5:*:*:*:*:*:*:*","cpe:2.3:a:apache:httpcore5_h2:5.3.5:*:*:*:*:*:*:*"],"name":"httpcore5-h2","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.5","type":"java-archive","version":"5.3.5","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpcore5-h2-5.3.5.jar","manifestName":"","pomArtifactID":"httpcore5-h2","archiveDigests":[{"value":"82014abcf597c051f00bf3aef2809063cb5024ae","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpcore5-h2-5.3.5.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpcore5-h2-5.3.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v3jc-474w-2wm6","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5-h2","version":"5.3.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v3jc-474w-2wm6","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-54428","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54428","date":"2026-10-08","epss":0.0087,"percentile":0.57533}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54428","https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3","https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e","https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v3jc-474w-2wm6","description":"Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK"},"relatedVulnerabilities":[{"id":"CVE-2026-54428","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-54428","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54428","date":"2026-10-08","epss":0.0087,"percentile":0.57533}],"urls":["https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54428","description":"Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied."}]},{"artifact":{"id":"d1f28aefeb5742fd","cpes":["cpe:2.3:a:apache:httpcore5-h2:5.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:httpcore5_h2:5.4:*:*:*:*:*:*:*"],"name":"httpcore5-h2","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.4","type":"java-archive","version":"5.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:org.apache.httpcomponents.core5:httpcore5-h2","manifestName":"","pomArtifactID":"httpcore5-h2","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v3jc-474w-2wm6","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5-h2","version":"5.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v3jc-474w-2wm6","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-54428","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54428","date":"2026-10-08","epss":0.0087,"percentile":0.57533}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54428","https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3","https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e","https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v3jc-474w-2wm6","description":"Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK"},"relatedVulnerabilities":[{"id":"CVE-2026-54428","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-54428","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54428","date":"2026-10-08","epss":0.0087,"percentile":0.57533}],"urls":["https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54428","description":"Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied."}]},{"artifact":{"id":"063d512429567e5f","cpes":["cpe:2.3:a:apache:httpcore5:5.3.5:*:*:*:*:*:*:*","cpe:2.3:a:apache:core5:5.3.5:*:*:*:*:*:*:*"],"name":"httpcore5","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.5","type":"java-archive","version":"5.3.5","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpcore5-5.3.5.jar","manifestName":"","pomArtifactID":"httpcore5","archiveDigests":[{"value":"172790b48b0d8cb5d74f28dcf712b5e5a70c3440","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpcore5-5.3.5.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpcore5-5.3.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hf6x-8p5f-cgmf","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5","version":"5.3.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hf6x-8p5f-cgmf","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-13","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54399","https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4","https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e","https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hf6x-8p5f-cgmf","description":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-54399","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"urls":["https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399","description":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length"}]},{"artifact":{"id":"6ac99c0ca606c95a","cpes":["cpe:2.3:a:apache:httpcore5:5.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:core5:5.4:*:*:*:*:*:*:*"],"name":"httpcore5","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.4","type":"java-archive","version":"5.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:org.apache.httpcomponents.core5:httpcore5","manifestName":"","pomArtifactID":"httpcore5","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hf6x-8p5f-cgmf","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5","version":"5.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hf6x-8p5f-cgmf","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-13","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54399","https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4","https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e","https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hf6x-8p5f-cgmf","description":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-54399","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"urls":["https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399","description":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length"}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-w49h-x2qq","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jppx-w49h-x2qq","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"risk":0.5103,"urls":["https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq","https://nvd.nist.gov/vuln/detail/CVE-2026-56745","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-w49h-x2qq","description":"Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-56745","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56745","description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-w49h-x2qq","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jppx-w49h-x2qq","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"risk":0.5103,"urls":["https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq","https://nvd.nist.gov/vuln/detail/CVE-2026-56745","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-w49h-x2qq","description":"Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-56745","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56745","description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-w49h-x2qq","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jppx-w49h-x2qq","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"risk":0.5103,"urls":["https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq","https://nvd.nist.gov/vuln/detail/CVE-2026-56745","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-w49h-x2qq","description":"Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-56745","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56745","description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6jqx-86gh-f27w","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6jqx-86gh-f27w","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://nvd.nist.gov/vuln/detail/CVE-2026-55831","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6jqx-86gh-f27w","description":"Netty SPDY SETTINGS frame count materializes unbounded settings map"},"relatedVulnerabilities":[{"id":"CVE-2026-55831","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55831","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6jqx-86gh-f27w","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6jqx-86gh-f27w","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://nvd.nist.gov/vuln/detail/CVE-2026-55831","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6jqx-86gh-f27w","description":"Netty SPDY SETTINGS frame count materializes unbounded settings map"},"relatedVulnerabilities":[{"id":"CVE-2026-55831","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55831","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6jqx-86gh-f27w","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6jqx-86gh-f27w","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://nvd.nist.gov/vuln/detail/CVE-2026-55831","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6jqx-86gh-f27w","description":"Netty SPDY SETTINGS frame count materializes unbounded settings map"},"relatedVulnerabilities":[{"id":"CVE-2026-55831","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55831","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mvh2-crg5-v77c","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mvh2-crg5-v77c","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://nvd.nist.gov/vuln/detail/CVE-2026-55833","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mvh2-crg5-v77c","description":"Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation"},"relatedVulnerabilities":[{"id":"CVE-2026-55833","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55833","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mvh2-crg5-v77c","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mvh2-crg5-v77c","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://nvd.nist.gov/vuln/detail/CVE-2026-55833","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mvh2-crg5-v77c","description":"Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation"},"relatedVulnerabilities":[{"id":"CVE-2026-55833","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55833","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mvh2-crg5-v77c","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mvh2-crg5-v77c","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://nvd.nist.gov/vuln/detail/CVE-2026-55833","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mvh2-crg5-v77c","description":"Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation"},"relatedVulnerabilities":[{"id":"CVE-2026-55833","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55833","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"06170f4af90bea6a","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http2-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"56375e341f0ca44079b1bfb62030285b9de5d713","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http2-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http2-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-93wv-jw9v-4972","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-93wv-jw9v-4972","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-08-01","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-56819","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56819","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972","https://nvd.nist.gov/vuln/detail/CVE-2026-56819","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-93wv-jw9v-4972","description":"Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-56819","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-56819","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56819","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56819","description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"37808196480bec20","cpes":["cpe:2.3:a:com.sun.mail:jakarta.mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:jakarta.mail:jakarta.mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:com.sun.mail:mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:jakarta.mail:mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:mail:jakarta.mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:sun:jakarta.mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:mail:mail:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:sun:mail:2.0.1:*:*:*:*:*:*:*"],"name":"jakarta.mail","purl":"pkg:maven/com.sun.mail/jakarta.mail@2.0.1","type":"java-archive","version":"2.0.1","language":"java","licenses":[],"metadata":{"pomGroupID":"com.sun.mail","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.sun.mail:jakarta.mail","manifestName":"","pomArtifactID":"jakarta.mail","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9342-92gg-6v29","versionConstraint":">=2.0.0,<2.0.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.sun.mail:jakarta.mail","version":"2.0.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9342-92gg-6v29","fix":{"state":"fixed","versions":["2.0.2"],"available":[{"date":"2026-04-17","kind":"first-observed","version":"2.0.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7962","cwe":"CWE-147","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2025-7962","date":"2026-10-08","epss":0.00782,"percentile":0.54619}],"risk":0.45942500000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-7962","https://gitlab.eclipse.org/security/cve-assignement/-/issues/67","https://github.com/eclipse-ee4j/angus-mail/commit/269099b652a0a5c2fa140f1296a18f0fbbea0d44","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290","http://www.openwall.com/lists/oss-security/2025/09/03/4","https://github.com/jakartaee/mail-api/issues/765","https://github.com/jakartaee/mail-api/pull/760","https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290#note_5320539"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9342-92gg-6v29","description":"Jakarta Mail vulnerable to SMTP Injection"},"relatedVulnerabilities":[{"id":"CVE-2025-7962","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7962","cwe":"CWE-147","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2025-7962","date":"2026-10-08","epss":0.00782,"percentile":0.54619}],"urls":["https://gitlab.eclipse.org/security/cve-assignement/-/issues/67","http://www.openwall.com/lists/oss-security/2025/09/03/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7962","description":"In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \\r and \\n UTF-8 characters to separate different messages."}]},{"artifact":{"id":"9e88f29158bfb7fe","cpes":["cpe:2.3:a:apache:log4j-api:2.25.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.25.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.4:*:*:*:*:*:*:*"],"name":"log4j-api","purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4","type":"java-archive","version":"2.25.4","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/sonarqube/elasticsearch/modules/apm/elastic-apm-agent-java8-1.55.6.jar:org.apache.logging.log4j:log4j-api","manifestName":"","pomArtifactID":"log4j-api","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/apm/elastic-apm-agent-java8-1.55.6.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/apm/elastic-apm-agent-java8-1.55.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.13.1,<2.25.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.25.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qv9r-c865-cp47","fix":{"state":"fixed","versions":["2.25.5"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"2.25.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"risk":0.459345,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization"},"relatedVulnerabilities":[{"id":"CVE-2026-49844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values."}]},{"artifact":{"id":"71460bfd97ca41d6","cpes":["cpe:2.3:a:apache:log4j-api:2.26.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.26.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.26.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.26.0:*:*:*:*:*:*:*"],"name":"log4j-api","purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.26.0","type":"java-archive","version":"2.26.0","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/sonarqube/elasticsearch/lib/log4j-api-2.26.0.jar","manifestName":"","pomArtifactID":"log4j-api","archiveDigests":[{"value":"ad52af0ecf054a7e3f275a2e180ee06d9c490951","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/log4j-api-2.26.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/log4j-api-2.26.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.26.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.26.0,<2.26.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.26.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qv9r-c865-cp47","fix":{"state":"fixed","versions":["2.26.1"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"2.26.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"risk":0.459345,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization"},"relatedVulnerabilities":[{"id":"CVE-2026-49844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values."}]},{"artifact":{"id":"ba484d2670579ce5","cpes":["cpe:2.3:a:apache:log4j-api:2.26.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.26.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.26.0:*:*:*:*:*:*:*"],"name":"log4j-api","purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.26.0","type":"java-archive","version":"2.26.0","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:org.apache.logging.log4j:log4j-api","manifestName":"","pomArtifactID":"log4j-api","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.26.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.26.0,<2.26.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.26.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qv9r-c865-cp47","fix":{"state":"fixed","versions":["2.26.1"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"2.26.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"risk":0.459345,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization"},"relatedVulnerabilities":[{"id":"CVE-2026-49844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.14.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"1f491c35db020428","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"f497a2a14f119b4d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"724566fffcfc5350","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=3.0.0,<3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["3.1.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=3.2.0,<3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["3.2.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.2.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2017-13716","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"risk":0.4197,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2017-13716"},"relatedVulnerabilities":[{"id":"CVE-2017-13716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-13716","date":"2026-10-08","epss":0.01399,"percentile":0.71642}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd)."}]},{"artifact":{"id":"a9639a66d41d0232","cpes":["cpe:2.3:a:apache:sshd-common:2.9.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:sshd_common:2.9.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:sshd:2.9.2:*:*:*:*:*:*:*"],"name":"sshd-common","purl":"pkg:maven/org.apache.sshd/sshd-common@2.9.2","type":"java-archive","version":"2.9.2","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.sshd","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:org.apache.sshd:sshd-common","manifestName":"","pomArtifactID":"sshd-common","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.12.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2326-hx7g-3m9r","versionConstraint":"<2.12.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.sshd:sshd-common","version":"2.9.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2326-hx7g-3m9r","fix":{"state":"fixed","versions":["2.12.0"],"available":[{"date":"2024-08-13","kind":"first-observed","version":"2.12.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41909","cwe":"CWE-354","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-41909","date":"2026-10-08","epss":0.00576,"percentile":0.45784}],"risk":0.41904,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-41909","https://github.com/apache/mina-sshd/issues/445","https://lists.apache.org/thread/vwf1ot8wx1njyy8n19j5j2tcnjnozt3b","https://github.com/apache/mina-sshd/pull/449","https://github.com/apache/mina-sshd/commit/315739e4e9d1dc7a4ff32ea64936982ed0b73e76","https://github.com/apache/mina-sshd/commit/6b0fd46f64bcb75eeeee31d65f10242660aad7c1","https://github.com/apache/mina-sshd/commit/7b2c781640a7a78a9455b86593a1f63c9e8cab92","https://github.com/apache/mina-sshd/releases/tag/sshd-2.12.0","https://security.netapp.com/advisory/ntap-20241011-0006"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2326-hx7g-3m9r","description":"Apache MINA SSHD: integrity check bypass"},"relatedVulnerabilities":[{"id":"CVE-2024-41909","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41909","cwe":"CWE-354","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-41909","date":"2026-10-08","epss":0.00576,"percentile":0.45784}],"urls":["https://github.com/apache/mina-sshd/issues/445","https://lists.apache.org/thread/vwf1ot8wx1njyy8n19j5j2tcnjnozt3b","https://security.netapp.com/advisory/ntap-20241011-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41909","description":"Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected."}]},{"artifact":{"id":"2670994e71cddd3a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.17.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"d8a5b83c22bd929d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.17.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"7f64486e5eb35363","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"19a6ad362834ee1b","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"f5e573de821de88c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"c48bebc342fd102b","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"753131354ae83beb","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=3.2.0,<=3.2.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["3.2.2"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.2.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"eb6e3a341adc5b20","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.84:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.84","type":"java-archive","version":"1.84","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/opt/sonarqube/elasticsearch/lib/tools/security-cli/bcprov-jdk18on-1.84.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"2d5651789941d2f8ae9b8771f23356de6b61e96b","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/tools/security-cli/bcprov-jdk18on-1.84.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/tools/security-cli/bcprov-jdk18on-1.84.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.85"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9pwp-9qqc-pr26","versionConstraint":"<1.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.84"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9pwp-9qqc-pr26","fix":{"state":"fixed","versions":["1.85"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"1.85"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8763","cwe":"CWE-295","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-8763","date":"2026-10-08","epss":0.0043,"percentile":0.35225}],"risk":0.3913,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-8763","https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE-2026-8763","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763","https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9pwp-9qqc-pr26","description":"Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI"},"relatedVulnerabilities":[{"id":"CVE-2026-8763","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8763","cwe":"CWE-295","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-8763","date":"2026-10-08","epss":0.0043,"percentile":0.35225}],"urls":["https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8763","description":"In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.11.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"f497a2a14f119b4d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"1f491c35db020428","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"724566fffcfc5350","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=3.0.0,<3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["3.1.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=3.2.0,<3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["3.2.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.2.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"69d0a0d2351d6c25","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"12f334a1dc9c6d2854c43ae314024dde8b3ad572","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"0a0312ef99dfae14","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"d8a5b83c22bd929d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"2670994e71cddd3a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"7c1200fbb29003c2","cpes":["cpe:2.3:a:io.netty.codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec","purl":"pkg:maven/io.netty/netty-codec@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec","archiveDigests":[{"value":"cf36e54dc81aa160a93780478727bdb3c3fa4600","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558v-64gr-wgg4","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"risk":0.3726,"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang"},"relatedVulnerabilities":[{"id":"CVE-2026-59901","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"e2e3afa6c408e73f","cpes":["cpe:2.3:a:io.netty.codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec","purl":"pkg:maven/io.netty/netty-codec@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec","archiveDigests":[{"value":"cf36e54dc81aa160a93780478727bdb3c3fa4600","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558v-64gr-wgg4","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"risk":0.3726,"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang"},"relatedVulnerabilities":[{"id":"CVE-2026-59901","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"00b4c320ab6df687","cpes":["cpe:2.3:a:io.netty.codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec","purl":"pkg:maven/io.netty/netty-codec@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec","archiveDigests":[{"value":"cf36e54dc81aa160a93780478727bdb3c3fa4600","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558v-64gr-wgg4","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"risk":0.3726,"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang"},"relatedVulnerabilities":[{"id":"CVE-2026-59901","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"69d0a0d2351d6c25","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"12f334a1dc9c6d2854c43ae314024dde8b3ad572","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"0a0312ef99dfae14","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"d8a5b83c22bd929d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"2670994e71cddd3a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"7f64486e5eb35363","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"19a6ad362834ee1b","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"f5e573de821de88c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"c48bebc342fd102b","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"753131354ae83beb","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4f6-jm68-57ww","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4f6-jm68-57ww","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"risk":0.362355,"urls":["https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4f6-jm68-57ww","description":"Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service"},"relatedVulnerabilities":[{"id":"CVE-2026-59899","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59899","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4f6-jm68-57ww","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4f6-jm68-57ww","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"risk":0.362355,"urls":["https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4f6-jm68-57ww","description":"Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service"},"relatedVulnerabilities":[{"id":"CVE-2026-59899","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59899","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4f6-jm68-57ww","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4f6-jm68-57ww","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"risk":0.362355,"urls":["https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4f6-jm68-57ww","description":"Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service"},"relatedVulnerabilities":[{"id":"CVE-2026-59899","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59899","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"eb6e3a341adc5b20","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.84:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.84","type":"java-archive","version":"1.84","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/opt/sonarqube/elasticsearch/lib/tools/security-cli/bcprov-jdk18on-1.84.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"2d5651789941d2f8ae9b8771f23356de6b61e96b","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/tools/security-cli/bcprov-jdk18on-1.84.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/tools/security-cli/bcprov-jdk18on-1.84.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.85"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qp49-qgx5-5m26","versionConstraint":"<1.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.84"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qp49-qgx5-5m26","fix":{"state":"fixed","versions":["1.85"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"1.85"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13506","cwe":"CWE-674","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-13506","date":"2026-10-08","epss":0.00442,"percentile":0.36375}],"risk":0.34476,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-13506","https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qp49-qgx5-5m26","description":"Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard"},"relatedVulnerabilities":[{"id":"CVE-2026-13506","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13506","cwe":"CWE-674","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-13506","date":"2026-10-08","epss":0.00442,"percentile":0.36375}],"urls":["https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13506","description":"In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.5.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.0.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"f497a2a14f119b4d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"1f491c35db020428","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"f497a2a14f119b4d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"1f491c35db020428","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"a078f754ea252a03","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"a078f754ea252a03","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.2","type":"java-archive","version":"2.22.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-python-plugin-5.31.0.36502.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.22.0,<=2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.22.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.22.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"724566fffcfc5350","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"724566fffcfc5350","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.2.0,<=3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.2.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.2.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1149","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"risk":0.28800000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1149"},"relatedVulnerabilities":[{"id":"CVE-2025-1149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1149","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1149","date":"2026-10-08","epss":0.00576,"percentile":0.45752}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.2745,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77214"},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.8.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"f497a2a14f119b4d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"1f491c35db020428","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.22.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.22.1:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1","type":"java-archive","version":"2.22.1","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/extensions/sonar-text-plugin-2.49.0.12346.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.22.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.22.0,<2.22.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.22.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.22.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.22.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"724566fffcfc5350","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.5:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.5","type":"java-archive","version":"3.1.5","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=3.0.0,<3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["3.1.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=3.2.0,<3.2.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["3.2.2"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.2.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"d94e2443cae4620e","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.11.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"fixed","versions":["1.11.1"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"1.11.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"bbc552abce93a937","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.0","type":"java-archive","version":"1.11.0","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.11.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"fixed","versions":["1.11.1"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"1.11.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"9da758d609c28f55","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-handler-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"567f8742a3d7a0a8be0401dada8fbdbaa7bf02b6","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-handler-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-handler-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"risk":0.250685,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext"},"relatedVulnerabilities":[{"id":"CVE-2026-75595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"e432abe2f907bfee","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-handler-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"567f8742a3d7a0a8be0401dada8fbdbaa7bf02b6","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-handler-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-handler-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"risk":0.250685,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext"},"relatedVulnerabilities":[{"id":"CVE-2026-75595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"2b1a2cff3627f27d","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-handler-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"567f8742a3d7a0a8be0401dada8fbdbaa7bf02b6","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-handler-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-handler-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"risk":0.250685,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext"},"relatedVulnerabilities":[{"id":"CVE-2026-75595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gcjf-9mgh-3p7g","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gcjf-9mgh-3p7g","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"risk":0.248775,"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gcjf-9mgh-3p7g","description":"Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder"},"relatedVulnerabilities":[{"id":"CVE-2026-59921","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59921","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gcjf-9mgh-3p7g","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gcjf-9mgh-3p7g","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"risk":0.248775,"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gcjf-9mgh-3p7g","description":"Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder"},"relatedVulnerabilities":[{"id":"CVE-2026-59921","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59921","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gcjf-9mgh-3p7g","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gcjf-9mgh-3p7g","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"risk":0.248775,"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gcjf-9mgh-3p7g","description":"Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder"},"relatedVulnerabilities":[{"id":"CVE-2026-59921","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59921","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4mp9-239f-g9hg","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4mp9-239f-g9hg","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"risk":0.24803499999999998,"urls":["https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4mp9-239f-g9hg","description":"Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation"},"relatedVulnerabilities":[{"id":"CVE-2026-59898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59898","description":"Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4mp9-239f-g9hg","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4mp9-239f-g9hg","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"risk":0.24803499999999998,"urls":["https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4mp9-239f-g9hg","description":"Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation"},"relatedVulnerabilities":[{"id":"CVE-2026-59898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59898","description":"Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4mp9-239f-g9hg","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4mp9-239f-g9hg","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"risk":0.24803499999999998,"urls":["https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4mp9-239f-g9hg","description":"Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation"},"relatedVulnerabilities":[{"id":"CVE-2026-59898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59898","description":"Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.15.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"risk":0.243225,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy"},"relatedVulnerabilities":[{"id":"CVE-2026-59888","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"69d0a0d2351d6c25","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"12f334a1dc9c6d2854c43ae314024dde8b3ad572","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-core-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"0a0312ef99dfae14","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"2670994e71cddd3a","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"d8a5b83c22bd929d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.17.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.17.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.17.2","type":"java-archive","version":"2.17.2","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/tools/plugin-cli/elasticsearch-x-content-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.17.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"4221642ecaea0c5f","cpes":["cpe:2.3:a:apache:httpclient5:5.5:*:*:*:*:*:*:*","cpe:2.3:a:apache:client5:5.5:*:*:*:*:*:*:*"],"name":"httpclient5","purl":"pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5","type":"java-archive","version":"5.5","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.httpcomponents.client5","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpclient5-5.5.jar","manifestName":"","pomArtifactID":"httpclient5","archiveDigests":[{"value":"4b3d253351cf74eb0ae8eb21ca5a5fb9815ef861","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpclient5-5.5.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-core/httpclient5-5.5.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.6.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hjcp-jmpx-g3qm","versionConstraint":">=5.0-alpha1,<5.6.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.client5:httpclient5","version":"5.5"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hjcp-jmpx-g3qm","fix":{"state":"fixed","versions":["5.6.3"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"5.6.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-64607","date":"2026-10-08","epss":0.00464,"percentile":0.3822}],"risk":0.23896,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-64607","https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94","https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hjcp-jmpx-g3qm","description":"Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-64607","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-64607","date":"2026-10-08","epss":0.00464,"percentile":0.3822}],"urls":["https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64607","description":"HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2."}]},{"artifact":{"id":"5e95a06d146ba333","cpes":["cpe:2.3:a:apache:httpclient5:5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:client5:5.6.1:*:*:*:*:*:*:*"],"name":"httpclient5","purl":"pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.6.1","type":"java-archive","version":"5.6.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.httpcomponents.client5","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:org.apache.httpcomponents.client5:httpclient5","manifestName":"","pomArtifactID":"httpclient5","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.6.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hjcp-jmpx-g3qm","versionConstraint":">=5.0-alpha1,<5.6.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.client5:httpclient5","version":"5.6.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hjcp-jmpx-g3qm","fix":{"state":"fixed","versions":["5.6.3"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"5.6.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-64607","date":"2026-10-08","epss":0.00464,"percentile":0.3822}],"risk":0.23896,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-64607","https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94","https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hjcp-jmpx-g3qm","description":"Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-64607","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-64607","date":"2026-10-08","epss":0.00464,"percentile":0.3822}],"urls":["https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64607","description":"HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2."}]},{"artifact":{"id":"06170f4af90bea6a","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http2-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"56375e341f0ca44079b1bfb62030285b9de5d713","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http2-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http2-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c69g-56f8-xwqj","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c69g-56f8-xwqj","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59900","date":"2026-10-08","epss":0.00398,"percentile":0.31911}],"risk":0.23680999999999996,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c69g-56f8-xwqj","description":"Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-59900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59900","date":"2026-10-08","epss":0.00398,"percentile":0.31911}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59900","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cqp-g7gg-8hr5","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cqp-g7gg-8hr5","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"risk":0.2346,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","https://nvd.nist.gov/vuln/detail/CVE-2026-56746","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","description":"Netty: Security Control Bypass via CORS Short-Circuit Failure"},"relatedVulnerabilities":[{"id":"CVE-2026-56746","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746","description":"Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cqp-g7gg-8hr5","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cqp-g7gg-8hr5","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"risk":0.2346,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","https://nvd.nist.gov/vuln/detail/CVE-2026-56746","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","description":"Netty: Security Control Bypass via CORS Short-Circuit Failure"},"relatedVulnerabilities":[{"id":"CVE-2026-56746","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746","description":"Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cqp-g7gg-8hr5","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cqp-g7gg-8hr5","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"risk":0.2346,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","https://nvd.nist.gov/vuln/detail/CVE-2026-56746","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","description":"Netty: Security Control Bypass via CORS Short-Circuit Failure"},"relatedVulnerabilities":[{"id":"CVE-2026-56746","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746","description":"Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.8.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5gvw-p9qm-jgwh","versionConstraint":">=3.2.0,<3.2.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5gvw-p9qm-jgwh","fix":{"state":"fixed","versions":["3.2.1"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"3.2.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59889","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59889","date":"2026-10-08","epss":0.00389,"percentile":0.30837}],"risk":0.22367499999999996,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh","https://nvd.nist.gov/vuln/detail/CVE-2026-59889","https://github.com/FasterXML/jackson-databind/issues/6060","https://github.com/FasterXML/jackson-databind/pull/6056","https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5gvw-p9qm-jgwh","description":"jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-59889","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59889","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59889","date":"2026-10-08","epss":0.00389,"percentile":0.30837}],"urls":["https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b","https://github.com/FasterXML/jackson-databind/issues/6060","https://github.com/FasterXML/jackson-databind/pull/6056","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59889","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"9da758d609c28f55","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-handler-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"567f8742a3d7a0a8be0401dada8fbdbaa7bf02b6","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-handler-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-handler-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"risk":0.22253,"urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-75596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"e432abe2f907bfee","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-handler-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"567f8742a3d7a0a8be0401dada8fbdbaa7bf02b6","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-handler-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-handler-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"risk":0.22253,"urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-75596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"2b1a2cff3627f27d","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-handler-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"567f8742a3d7a0a8be0401dada8fbdbaa7bf02b6","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-handler-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-handler-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"risk":0.22253,"urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-75596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"7bf5ce0eb867b441","cpes":["cpe:2.3:a:io.projectreactor.netty:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:io.projectreactor.netty:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor-netty-http:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor-netty-http:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor_netty_http:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor_netty_http:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:projectreactor:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:projectreactor:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor-netty:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor-netty:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor_netty:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor_netty:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:io.projectreactor.netty:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:netty:reactor-netty-http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:netty:reactor_netty_http:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor-netty-http:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor_netty_http:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:projectreactor:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor-netty:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor_netty:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:reactor:netty:1.0.45:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty:1.0.45:*:*:*:*:*:*:*"],"name":"reactor-netty-http","purl":"pkg:maven/io.projectreactor.netty/reactor-netty-http@1.0.45","type":"java-archive","version":"1.0.45","language":"java","licenses":[],"metadata":{"pomGroupID":"io.projectreactor.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/reactor-netty-http-1.0.45.jar","manifestName":"","pomArtifactID":"reactor-netty-http","archiveDigests":[{"value":"f24886830010329239a2f10f19727ea420898fba","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/reactor-netty-http-1.0.45.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/reactor-netty-http-1.0.45.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4q2v-9p7v-3v22","versionConstraint":"<1.2.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.projectreactor.netty:reactor-netty-http","version":"1.0.45"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4q2v-9p7v-3v22","fix":{"state":"fixed","versions":["1.2.8"],"available":[{"date":"2025-07-17","kind":"first-observed","version":"1.2.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22227","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22227","date":"2026-10-08","epss":0.00377,"percentile":0.29603}],"risk":0.20923499999999998,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-22227","https://spring.io/security/cve-2025-22227","https://github.com/reactor/reactor-netty/commit/522892307ea89bf24fe634e8bfea35728c9bf411"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4q2v-9p7v-3v22","description":"Reactor Netty HTTP is vulnerable to credential leaks during chained redirects"},"relatedVulnerabilities":[{"id":"CVE-2025-22227","cvss":[{"type":"Secondary","source":"security@vmware.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22227","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22227","date":"2026-10-08","epss":0.00377,"percentile":0.29603}],"urls":["https://spring.io/security/cve-2025-22227"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22227","description":"In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"16602232eb821461","cpes":["cpe:2.3:a:io.netty.codec-dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-dns:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-dns:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_dns:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_dns:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-dns:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-dns:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_dns:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_dns:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-dns:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-dns:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_dns:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_dns:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-dns:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_dns:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-dns","purl":"pkg:maven/io.netty/netty-codec-dns@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-dns-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-dns","archiveDigests":[{"value":"0814e353f6c5f9383f2b93d941961f89565f4161","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-dns-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-dns-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mfg7-5gfp-c4w3","versionConstraint":"<=4.1.135.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-dns","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mfg7-5gfp-c4w3","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-25","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73508","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73508","date":"2026-10-08","epss":0.00382,"percentile":0.30064}],"risk":0.19673,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3","https://github.com/netty/netty/pull/17063","https://github.com/netty/netty/pull/17065","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mfg7-5gfp-c4w3","description":"Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names"},"relatedVulnerabilities":[{"id":"CVE-2026-73508","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73508","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73508","date":"2026-10-08","epss":0.00382,"percentile":0.30064}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73508","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"d94e2443cae4620e","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"d94e2443cae4620e","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"d94e2443cae4620e","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"bbc552abce93a937","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.0","type":"java-archive","version":"1.11.0","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"bbc552abce93a937","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.0","type":"java-archive","version":"1.11.0","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"bbc552abce93a937","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.0","type":"java-archive","version":"1.11.0","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hgj6-7826-r7m5","versionConstraint":">=2.0.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hgj6-7826-r7m5","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"risk":0.18952000000000002,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://nvd.nist.gov/vuln/detail/CVE-2026-54514"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hgj6-7826-r7m5","description":"jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)"},"relatedVulnerabilities":[{"id":"CVE-2026-54514","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"urls":["https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54514","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"189797159b08d016","cpes":["cpe:2.3:a:org.postgresql.osgi.PGBundleActivator:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql-global-development-group:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql_global_development_group:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.osgi.PGBundleActivator:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql-global-development-group:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql_global_development_group:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.osgi.PGBundleActivator:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.osgi.PGBundleActivator:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql-global-development-group:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql-global-development-group:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql_global_development_group:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql_global_development_group:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.jdbc:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle-corporation:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle_corporation:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:PGBundleActivator:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.jdbc:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle-corporation:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle_corporation:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:PGBundleActivator:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.jdbc:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql.jdbc:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle-corporation:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle-corporation:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle_corporation:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:oracle_corporation:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:PGBundleActivator:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:PGBundleActivator:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:jdbc:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:osgi:PGBundleActivator:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:org.postgresql:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:jdbc:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:osgi:postgresql:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:postgresql:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:jdbc:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:jdbc:osgi:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:osgi:jdbc:42.7.11:*:*:*:*:*:*:*","cpe:2.3:a:osgi:osgi:42.7.11:*:*:*:*:*:*:*"],"name":"postgresql","purl":"pkg:maven/org.postgresql/postgresql@42.7.11","type":"java-archive","version":"42.7.11","language":"java","licenses":["BSD-2-Clause"],"metadata":{"pomGroupID":"org.postgresql","virtualPath":"/opt/sonarqube/lib/jdbc/postgresql/postgresql-42.7.11.jar","manifestName":"","pomArtifactID":"postgresql","archiveDigests":[{"value":"4c21cdd1b3938f400703716d37c4e8ca4d332808","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/lib/jdbc/postgresql/postgresql-42.7.11.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/jdbc/postgresql/postgresql-42.7.11.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"42.7.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j92g-9f8w-j867","versionConstraint":">=42.7.4,<42.7.12 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.postgresql:postgresql","version":"42.7.11"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j92g-9f8w-j867","fix":{"state":"fixed","versions":["42.7.12"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"42.7.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54291","cwe":"CWE-636","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54291","cwe":"CWE-757","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54291","date":"2026-10-08","epss":0.00236,"percentile":0.13424}],"risk":0.18525999999999998,"urls":["https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867","https://nvd.nist.gov/vuln/detail/CVE-2026-54291","https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99","https://github.com/ongres/scram/releases/tag/3.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j92g-9f8w-j867","description":"PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms"},"relatedVulnerabilities":[{"id":"CVE-2026-54291","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54291","cwe":"CWE-636","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54291","cwe":"CWE-757","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54291","date":"2026-10-08","epss":0.00236,"percentile":0.13424}],"urls":["https://github.com/ongres/scram/releases/tag/3.3","https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99","https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54291","description":"pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1152"},"relatedVulnerabilities":[{"id":"CVE-2025-1152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1152","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1152","date":"2026-10-08","epss":0.00616,"percentile":0.47904}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1150","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"risk":0.18359999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1150"},"relatedVulnerabilities":[{"id":"CVE-2025-1150","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1150","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1150","date":"2026-10-08","epss":0.00612,"percentile":0.4769}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-1151","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"risk":0.18209999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-1151"},"relatedVulnerabilities":[{"id":"CVE-2025-1151","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1151","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1151","date":"2026-10-08","epss":0.00607,"percentile":0.47408}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\""}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.174,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102633"},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"541d77fcd7d3c807","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.0","type":"java-archive","version":"2.15.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"0d41caa3a4e9f85382702a059a65c512f85ac230","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/jackson-databind-2.15.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vvgp-rfg2-7rr6","versionConstraint":">=2.0.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vvgp-rfg2-7rr6","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"risk":0.161195,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6","https://nvd.nist.gov/vuln/detail/CVE-2026-77310","https://github.com/FasterXML/jackson-databind/pull/6058","https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vvgp-rfg2-7rr6","description":"jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-77310","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77310","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"6080c5b2c8974e53","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.2.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.2.0","type":"java-archive","version":"3.2.0","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vvgp-rfg2-7rr6","versionConstraint":">=3.2.0,<3.2.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.2.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vvgp-rfg2-7rr6","fix":{"state":"fixed","versions":["3.2.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"3.2.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"risk":0.161195,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6","https://nvd.nist.gov/vuln/detail/CVE-2026-77310","https://github.com/FasterXML/jackson-databind/pull/6058","https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vvgp-rfg2-7rr6","description":"jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-77310","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77310","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"25abd8999d67bbb0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-inference/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8c42-7qj2-3j46","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8c42-7qj2-3j46","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-08-18","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"risk":0.14145,"urls":["https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8c42-7qj2-3j46","description":"Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite"},"relatedVulnerabilities":[{"id":"CVE-2026-59903","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"urls":["https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59903","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"860479dd347e78a5","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/transport-netty4/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8c42-7qj2-3j46","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8c42-7qj2-3j46","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-08-18","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"risk":0.14145,"urls":["https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8c42-7qj2-3j46","description":"Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite"},"relatedVulnerabilities":[{"id":"CVE-2026-59903","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"urls":["https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59903","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"f6b7647b8b5eb6ce","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.1.135.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.1.135.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.1.135.Final","type":"java-archive","version":"4.1.135.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"69d785784208bae296fa74d802772687c6947754","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/modules/x-pack-security/netty-codec-http-4.1.135.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8c42-7qj2-3j46","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.1.135.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8c42-7qj2-3j46","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-08-18","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"risk":0.14145,"urls":["https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8c42-7qj2-3j46","description":"Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite"},"relatedVulnerabilities":[{"id":"CVE-2026-59903","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"urls":["https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59903","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"risk":0.122,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69651"},"relatedVulnerabilities":[{"id":"CVE-2025-69651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69651","date":"2026-10-08","epss":0.00244,"percentile":0.14363}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-11495","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"risk":0.11850000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-11495"},"relatedVulnerabilities":[{"id":"CVE-2025-11495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-11495","cwe":"CWE-122","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-11495","date":"2026-10-08","epss":0.00237,"percentile":0.13455}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch."}]},{"artifact":{"id":"d8bab1fda988e859","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.32:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.32","type":"java-archive","version":"1.5.32","language":"java","licenses":[],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:ch.qos.logback:logback-core","manifestName":"","pomArtifactID":"logback-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p47f-322f-whfh","versionConstraint":"<=1.5.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p47f-322f-whfh","fix":{"state":"fixed","versions":["1.5.33"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"1.5.33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:Green","metrics":{"baseScore":1.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9828","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-9828","date":"2026-10-08","epss":0.00545,"percentile":0.43985}],"risk":0.11445,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-9828","https://logback.qos.ch/news.html#1.5.33"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p47f-322f-whfh","description":"QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-9828","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9828","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-9828","date":"2026-10-08","epss":0.00545,"percentile":0.43985}],"urls":["https://logback.qos.ch/news.html#1.5.33"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9828","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate objects from\n classes in the java.lang and java.util packages that are not explicitly\n blocked.\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.32 inclusive."}]},{"artifact":{"id":"d94e2443cae4620e","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"bbc552abce93a937","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.11.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.11.0","type":"java-archive","version":"1.11.0","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar:at.yawk.lz4:lz4-java","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/sonar-application-26.9.0.129388.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.11.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66863","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66863"},"relatedVulnerabilities":[{"id":"CVE-2025-66863","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66863","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66865","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"risk":0.11279999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66865"},"relatedVulnerabilities":[{"id":"CVE-2025-66865","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66865","date":"2026-10-08","epss":0.00376,"percentile":0.2948}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66862","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"risk":0.11100000000000002,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66862"},"relatedVulnerabilities":[{"id":"CVE-2025-66862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66862","date":"2026-10-08","epss":0.0037,"percentile":0.28897}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"d8bab1fda988e859","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.32:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.32:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.32","type":"java-archive","version":"1.5.32","language":"java","licenses":[],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:ch.qos.logback:logback-core","manifestName":"","pomArtifactID":"logback-core","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.34"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jhq6-gfmj-v8fx","versionConstraint":"<1.5.34 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.32"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jhq6-gfmj-v8fx","fix":{"state":"fixed","versions":["1.5.34"],"available":[{"date":"2026-07-16","kind":"first-observed","version":"1.5.34"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10532","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-10532","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"risk":0.10915,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-10532","https://logback.qos.ch/news.html#1.5.34","https://github.com/qos-ch/logback/releases/tag/v_1.5.34"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jhq6-gfmj-v8fx","description":"Logback vulnerable to Object Injection through HardenedObjectInputStream modules"},"relatedVulnerabilities":[{"id":"CVE-2026-10532","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10532","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-10532","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"urls":["https://logback.qos.ch/news.html#1.5.34"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10532","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\n\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.33 inclusive."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90801","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"risk":0.104,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90801"},"relatedVulnerabilities":[{"id":"CVE-2026-90801","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90801","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90801","cwe":"CWE-120","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90801","date":"2026-10-08","epss":0.00208,"percentile":0.09949}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34442","https://vuldb.com/cve/CVE-2026-90801","https://vuldb.com/submit/920276","https://vuldb.com/vuln/403303","https://vuldb.com/vuln/403303/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90801","description":"A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.1015,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66382"},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"risk":0.1005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90803"},"relatedVulnerabilities":[{"id":"CVE-2026-90803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":5.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90803","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90803","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90803","date":"2026-10-08","epss":0.00201,"percentile":0.09107}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20readwrite%20and%20SEGV%20in%20%60elf_x86_64_relocate_section%60%20(bfdelf64-x86-64.c4530%20%204835)%20via%20malformed%20relocation.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34444","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=471130b39c03623ec6d78ece377ff4da3f6bfe7b","https://vuldb.com/cve/CVE-2026-90803","https://vuldb.com/submit/920280","https://vuldb.com/vuln/403305","https://vuldb.com/vuln/403305/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90803","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90804","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90804","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"risk":0.0985,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90804"},"relatedVulnerabilities":[{"id":"CVE-2026-90804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":3.4,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90804","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90804","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90804","date":"2026-10-08","epss":0.00197,"percentile":0.08612}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/Heap%20OOB%20write%20%20negative-size%20%60memmove%60%20%20SEGV%20in%20%60_bfd_elf_write_section_eh_frame%60%20(bfdelf-eh-frame.c2064%20%202083%20%202193)%20via%20malformed%20%60.eh_frame%60.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34445","https://vuldb.com/cve/CVE-2026-90804","https://vuldb.com/submit/920281","https://vuldb.com/vuln/403306","https://vuldb.com/vuln/403306/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90804","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6846","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"risk":0.098,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6846"},"relatedVulnerabilities":[{"id":"CVE-2026-6846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-6846","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6846","date":"2026-10-08","epss":0.00196,"percentile":0.08543}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3441"},"relatedVulnerabilities":[{"id":"CVE-2026-3441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3441","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3442","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"risk":0.0955,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3442"},"relatedVulnerabilities":[{"id":"CVE-2026-3442","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3442","date":"2026-10-08","epss":0.00191,"percentile":0.0803}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90828","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90828","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"risk":0.094,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90828"},"relatedVulnerabilities":[{"id":"CVE-2026-90828","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90828","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90828","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90828","date":"2026-10-08","epss":0.00188,"percentile":0.07695}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16882","https://sourceware.org/bugzilla/show_bug.cgi?id=34450","https://vuldb.com/cve/CVE-2026-90828","https://vuldb.com/submit/925227","https://vuldb.com/vuln/403330","https://vuldb.com/vuln/403330/cti","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90828","description":"A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66866","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"risk":0.0933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66866"},"relatedVulnerabilities":[{"id":"CVE-2025-66866","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66866","date":"2026-10-08","epss":0.00311,"percentile":0.21996}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90802","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"risk":0.0915,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90802"},"relatedVulnerabilities":[{"id":"CVE-2026-90802","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:P/A:P","metrics":{"baseScore":3.2,"impactScore":5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90802","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90802","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90802","date":"2026-10-08","epss":0.00183,"percentile":0.07194}],"urls":["https://github.com/r1ck9-2q/cve_summit/blob/main/SEGV%20in%20%60bfd_putl64%60%20(bfdlibbfd.c989)%20during%20relocation%20output%20via%20malformed%20ELF.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34443","https://vuldb.com/cve/CVE-2026-90802","https://vuldb.com/submit/920277","https://vuldb.com/vuln/403304","https://vuldb.com/vuln/403304/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90802","description":"A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69652","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69652"},"relatedVulnerabilities":[{"id":"CVE-2025-69652","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69652","date":"2026-10-08","epss":0.00179,"percentile":0.06865}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69648","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69648"},"relatedVulnerabilities":[{"id":"CVE-2025-69648","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69648","date":"2026-10-08","epss":0.00179,"percentile":0.06845}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91781"},"relatedVulnerabilities":[{"id":"CVE-2026-91781","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91781","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91781","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91781","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34449","https://sourceware.org/bugzilla/show_bug.cgi?id=34449","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7322e9bc30cb282575a701c307851fd3d66fee68","https://vuldb.com/cve/CVE-2026-91781","https://vuldb.com/submit/933336","https://vuldb.com/vuln/404052","https://vuldb.com/vuln/404052/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91781","description":"A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91782","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"risk":0.08750000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91782"},"relatedVulnerabilities":[{"id":"CVE-2026-91782","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91782","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91782","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91782","date":"2026-10-08","epss":0.00175,"percentile":0.06371}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34448","https://sourceware.org/bugzilla/show_bug.cgi?id=34448","https://vuldb.com/cve/CVE-2026-91782","https://vuldb.com/submit/933335","https://vuldb.com/vuln/404053","https://vuldb.com/vuln/404053/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91782","description":"A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended."}]},{"artifact":{"id":"66f54d89b7a27eab","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.13.2\\+dfsg-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.13.2%2Bdfsg-1ubuntu0.1?arch=amd64&distro=ubuntu-24.04&upstream=freetype","type":"deb","version":"2.13.2+dfsg-1ubuntu0.1","language":"","licenses":["BSD-3-Clause","BSL-1.0","Expat","FSFAP","FTL","GPL-2","GPL-2+","GPL-3","GPL-3+","MIT-Modern-Variant","MIT-SMC","OpenGroup-MIT","Public-Domain","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.13.2+dfsg-1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95512","versionConstraint":"< 2.13.2+dfsg-1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"freetype","version":"2.13.2+dfsg-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95512","fix":{"state":"fixed","versions":["2.13.2+dfsg-1ubuntu0.2"],"available":[{"date":"2026-10-06","kind":"advisory","version":"2.13.2+dfsg-1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"risk":0.087,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95512"},"relatedVulnerabilities":[{"id":"CVE-2026-95512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"urls":["https://access.redhat.com/errata/RHSA-2026:74952","https://access.redhat.com/security/cve/CVE-2026-95512","https://bugzilla.redhat.com/show_bug.cgi?id=2462295","https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"risk":0.0865,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69645"},"relatedVulnerabilities":[{"id":"CVE-2025-69645","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69645","date":"2026-10-08","epss":0.00173,"percentile":0.06118}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"risk":0.086,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90829"},"relatedVulnerabilities":[{"id":"CVE-2026-90829","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90829","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90829","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90829","date":"2026-10-08","epss":0.00172,"percentile":0.06038}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16883","https://sourceware.org/bugzilla/show_bug.cgi?id=34451","https://vuldb.com/cve/CVE-2026-90829","https://vuldb.com/submit/925228","https://vuldb.com/vuln/403331","https://vuldb.com/vuln/403331/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90829","description":"A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91779","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91779","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91779"},"relatedVulnerabilities":[{"id":"CVE-2026-91779","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91779","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91779","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91779","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/blob/main/bugzilla/issues/34446.md","https://sourceware.org/bugzilla/show_bug.cgi?id=34446","https://vuldb.com/cve/CVE-2026-91779","https://vuldb.com/submit/933333","https://vuldb.com/vuln/404050","https://vuldb.com/vuln/404050/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91779","description":"A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-91780","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-91780","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"risk":0.08499999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-91780"},"relatedVulnerabilities":[{"id":"CVE-2026-91780","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91780","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-91780","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-91780","date":"2026-10-08","epss":0.0017,"percentile":0.05731}],"urls":["https://github.com/Ech06/CVE_submit/tree/main/bugzilla/pocs/34447","https://sourceware.org/bugzilla/show_bug.cgi?id=34447","https://vuldb.com/cve/CVE-2026-91780","https://vuldb.com/submit/933334","https://vuldb.com/vuln/404051","https://vuldb.com/vuln/404051/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91780","description":"A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90831","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90831","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90831"},"relatedVulnerabilities":[{"id":"CVE-2026-90831","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90831","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90831","date":"2026-10-08","epss":0.00168,"percentile":0.05585}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16886","https://sourceware.org/bugzilla/show_bug.cgi?id=34454","https://vuldb.com/cve/CVE-2026-90831","https://vuldb.com/submit/925230","https://vuldb.com/vuln/403333","https://vuldb.com/vuln/403333/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90831","description":"A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4647"},"relatedVulnerabilities":[{"id":"CVE-2026-4647","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4647","date":"2026-10-08","epss":0.00168,"percentile":0.05557}],"urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-90830","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-90830","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-90830"},"relatedVulnerabilities":[{"id":"CVE-2026-90830","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90830","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-90830","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-90830","date":"2026-10-08","epss":0.00165,"percentile":0.05172}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16884","https://sourceware.org/bugzilla/show_bug.cgi?id=34452","https://vuldb.com/cve/CVE-2026-90830","https://vuldb.com/submit/925229","https://vuldb.com/vuln/403332","https://vuldb.com/vuln/403332/cti","https://www.gnu.org/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90830","description":"A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69646","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69646"},"relatedVulnerabilities":[{"id":"CVE-2025-69646","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69646","date":"2026-10-08","epss":0.00161,"percentile":0.04709}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69647","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69647"},"relatedVulnerabilities":[{"id":"CVE-2025-69647","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69647","date":"2026-10-08","epss":0.00158,"percentile":0.04334}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19548","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"risk":0.0775,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19548"},"relatedVulnerabilities":[{"id":"CVE-2026-19548","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19548","date":"2026-10-08","epss":0.00155,"percentile":0.04065}],"urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15003"},"relatedVulnerabilities":[{"id":"CVE-2026-15003","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15003","date":"2026-10-08","epss":0.00151,"percentile":0.03695}],"urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6844","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6844"},"relatedVulnerabilities":[{"id":"CVE-2026-6844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6844","date":"2026-10-08","epss":0.00147,"percentile":0.03417}],"urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"risk":0.07319999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66864"},"relatedVulnerabilities":[{"id":"CVE-2025-66864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-66864","date":"2026-10-08","epss":0.00244,"percentile":0.1428}],"urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file."}]},{"artifact":{"id":"aa8f9b7d55a51e0b","cpes":["cpe:2.3:a:binutils:binutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/ubuntu/binutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"a1f76c75d57674c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/ubuntu/binutils-common@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"247e2ce255dab90a","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/ubuntu/binutils-x86-64-linux-gnu@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"b2e04e5c1575b3bd","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/ubuntu/libbinutils@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"3e70238dbe6d70ec","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/ubuntu/libctf-nobfd0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"5b6339752fdff17e","cpes":["cpe:2.3:a:libctf0:libctf0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/ubuntu/libctf0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"0a154df7b4408871","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/ubuntu/libgprofng0@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"6970da29e00d4760","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.42-4ubuntu2.10:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/ubuntu/libsframe1@2.42-4ubuntu2.10?arch=amd64&distro=ubuntu-24.04&upstream=binutils","type":"deb","version":"2.42-4ubuntu2.10","language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"binutils","version":"2.42-4ubuntu2.10"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6845","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"risk":0.0725,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6845"},"relatedVulnerabilities":[{"id":"CVE-2026-6845","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-6845","date":"2026-10-08","epss":0.00145,"percentile":0.03242}],"urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"23f774ea0787616c","cpes":["cpe:2.3:a:net.i2p.crypto:eddsa:0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:crypto:eddsa:0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:eddsa:eddsa:0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:i2p:eddsa:0.3.0:*:*:*:*:*:*:*"],"name":"eddsa","purl":"pkg:maven/net.i2p.crypto/eddsa@0.3.0","type":"java-archive","version":"0.3.0","language":"java","licenses":["CC0 1.0 Universal"],"metadata":{"pomGroupID":"net.i2p.crypto","virtualPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar:net.i2p.crypto:eddsa","manifestName":"","pomArtifactID":"eddsa","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/lib/scanner/sonar-scanner-engine-community-13.7.0.4455.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p53j-g8pw-4w5f","versionConstraint":"<=0.3.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"net.i2p.crypto:eddsa","version":"0.3.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p53j-g8pw-4w5f","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36843","cwe":"CWE-347","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2020-36843","date":"2026-10-08","epss":0.00143,"percentile":0.03108}],"risk":0.066495,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-36843","https://github.com/str4d/ed25519-java/issues/82#issue-727629226","https://eprint.iacr.org/2020/1244","https://github.com/i2p/i2p.i2p/commit/d7d1dcb5399c61cf2916ccc45aa25b0209c88712#diff-658f7b1aa34b58d27796fccdb8b756c72702d64ae44703374960f1cb89a5a5c3"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p53j-g8pw-4w5f","description":"Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check"},"relatedVulnerabilities":[{"id":"CVE-2020-36843","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-36843","cwe":"CWE-347","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2020-36843","date":"2026-10-08","epss":0.00143,"percentile":0.03108}],"urls":["https://eprint.iacr.org/2020/1244","https://github.com/str4d/ed25519-java/issues/82#issue-727629226"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36843","description":"The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"21ecd7363833c5d4","cpes":["cpe:2.3:a:jline-reader:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline-reader:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline_reader:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-reader:3.21.0:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_reader:3.21.0:*:*:*:*:*:*:*"],"name":"jline-reader","purl":"pkg:maven/org.jline/jline-reader@3.21.0","type":"java-archive","version":"3.21.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar:org.jline:jline-reader","manifestName":"","pomArtifactID":"jline-reader","archiveDigests":null},"locations":[{"path":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/opt/sonarqube/elasticsearch/bin/elasticsearch-sql-cli-9.4.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5q95-hrpc-m3w3","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-reader","version":"3.21.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5q95-hrpc-m3w3","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77420","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77420","date":"2026-10-08","epss":0.00123,"percentile":0.0183}],"risk":0.06457500000000001,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5q95-hrpc-m3w3","description":"JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable"},"relatedVulnerabilities":[{"id":"CVE-2026-77420","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77420","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77420","date":"2026-10-08","epss":0.00123,"percentile":0.0183}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77420","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:36360f22a49237dbaaf02e02e34d488021150d50c64dc9fdfbfaa54a7672a55b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e0c03a3c620e3e3673d95283810c1edc2661e4debeb5da9f904ee004ffb6ecac","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:24:30.848Z","grype_db_version":"2026-10-09T06:32:32.000Z"}