{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a659ed63-88b4-44e3-b7f3-a2c448cefc5f",
  "version": 1,
  "metadata": {
    "timestamp": "2026-10-09T15:09:40+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "8ef3deb1-4520-4115-90ee-f13c4b78fbcc",
      "type": "application",
      "name": "confluent-control-center-next-gen-2.5.1-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2026-10050",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        173,
        303
      ],
      "description": "In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `\u03b1\u03b2123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-security to version 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10050"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10050"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-10050"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/15136"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15160"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15183"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10050"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10050"
        }
      ],
      "published": "2026-08-04T11:22:43+00:00",
      "updated": "2026-08-08T00:38:56+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-10051",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        200
      ],
      "description": "In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection.\nSubsequent request that do not have trailers report the trailers of the first request.\nSubsequent request that do have trailers report the union of trailers of the first request and the current request.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-server to version 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10051"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10051"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-10051"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/72206b3ea623cf7ed8729b47a83ee628ff10e8eb"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/dc27e8d3ab743fe27935ea2d8c41756eb6c5bae9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15162"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15163"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-f4v5-65jj-pcr2"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10051"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10051"
        }
      ],
      "published": "2026-07-14T09:16:39+00:00",
      "updated": "2026-07-14T18:41:52+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-106449",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        674
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106449"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106449"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106449"
        },
        {
          "url": "https://github.com/advisories/GHSA-343h-94h5-c4wr"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106449"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106449"
        }
      ],
      "published": "2026-10-06T20:17:26+00:00",
      "updated": "2026-10-07T17:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ]
    },
    {
      "id": "CVE-2026-106450",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106450"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106450"
        },
        {
          "url": "https://github.com/advisories/GHSA-gm45-99xc-r7wv"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106450"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106450"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-09T02:16:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ]
    },
    {
      "id": "CVE-2026-106451",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        367,
        377
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106451"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106451"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106451"
        },
        {
          "url": "https://github.com/advisories/GHSA-mcr4-qmvw-px4g"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106451"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106451"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T19:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ]
    },
    {
      "id": "CVE-2026-106452",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        789
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106452"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106452"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106452"
        },
        {
          "url": "https://github.com/advisories/GHSA-4v53-57pg-c464"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106452"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106452"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T13:58:29+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ]
    },
    {
      "id": "CVE-2026-106453",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        789
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106453"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106453"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106453"
        },
        {
          "url": "https://github.com/advisories/GHSA-6cx8-rjf8-pr8g"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106453"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106453"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T17:16:48+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ]
    },
    {
      "id": "CVE-2026-107226",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "description": "### Impact\nThe cookie store ignores the scheme a `Set-Cookie` arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the `Secure` attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only `Secure` handling is on retrieval, where a Secure cookie is not sent over plaintext.\n\nSo anyone who can answer a plaintext request to a site can set, replace or delete the site's `Secure` cookies, and the next HTTPS request carries the attacker's value back inside TLS:\n\n```\nhttp://example.com   ->  Set-Cookie: SID=attacker-value; Secure; Path=/\nhttps://example.com  ->  Cookie: SID=attacker-value\n```\n\nThis does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie:\n\n```\nhttp://insecure.example.com  ->  Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/\nhttps://bank.example.com     ->  Cookie: SID=attacker-value\n```\n\nA plaintext `Set-Cookie` of the same name, domain and path overwrites a Secure cookie, and one with `Max-Age=0` deletes it. Depending on what the application does with the cookie, this is session fixation into the HTTPS session, an overwritten CSRF token, or the removal of a cookie the site relies on. Unlike GHSA-qjr7-w8pj-pmv9, which can only add a cookie, this replaces or deletes one, hence Integrity: High; the harm lands on the HTTPS site, hence Scope: Changed.\n\n### Affected versions\n* 3.x: up to and including 3.0.13\n* 2.x: from 2.1.0, when the cookie store was introduced, up to and including 2.16.1\n\n### Patches\nFixed in 3.0.14 on the 3.x line. A cookie with the `Secure` attribute is ignored unless the request was secure, and a non-Secure cookie from a request that did not use TLS is ignored when it would overlay a Secure cookie of the same name whose path its own path falls under. A plaintext response can therefore no longer plant, overwrite or delete a `Secure` cookie.\n\nWhen several cookies of one name match a request, the client sends only the first, so the order in which the store returns them decides which one is used. That order is now: on a secure request, cookies received in a secure context (HTTPS, WSS or plaintext loopback) first; then the request host's own cookies before cookies set for a parent domain; then, within one host, longer paths first. A plaintext attacker cannot outrank a cookie the site set over HTTPS by ordering or padding its own cookies, or by setting one before the site sets its own.\n\nPlaintext requests to `localhost`, or to an address literal that is a loopback address, count as secure, so a development server that sets `Secure` cookies over `http://localhost` gets them back. This is limited to the cookies such a server set itself: a `Secure` cookie that arrived over HTTPS is never sent over plaintext, loopback included, and a plaintext loopback port cannot overlay it. Numeric spellings that are not address literals, such as `127.0.0.256`, and names under `localhost` are not treated as loopback, because the client resolves them as names.\n\nThe 2.x line is end of life and will not receive a fix. Upgrade to 3.0.14.\n\n### Workarounds\nDo not share one `CookieStore` between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site. Disabling the cookie store also avoids it.\n\n### Details\n`ThreadSafeCookieStore.add(Uri, Cookie)` reduces the request to its host and path before storing, so the scheme never reaches the code that decides whether to keep a cookie. `get(Uri)` does read it, but only to leave `Secure` cookies out of plaintext requests.\n\nA narrower form survives the two storage rules on their own. The step 16 path test is one-way by design, so a plaintext `SID` for `Path=/` is legitimately stored beside a Secure `SID` for `Path=/account`, and both match a request under `/account`. The store returned matching cookies in hash order, and the client keeps only the first cookie of each name when it builds the request (`RequestBuilderBase.addCookieIfUnset`), so an attacker could decide which one was sent, for example by padding one plaintext response with filler cookies. The ordering described above closes it.\n\nThe fix does not stop an HTTPS host under the same site from setting a domain cookie for a name the request host never sets itself. Only a `__Host-` cookie name prefix prevents that, and the client does not enforce cookie name prefixes.\n\n### Attribution\n\nAI-assisted tools were used to support discovery and analysis.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107226"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6ec7ee45034d154f502852a962d2891746fb82c1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg"
        }
      ],
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107227",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        409
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107227"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107227"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107227"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107227"
        }
      ],
      "published": "2026-10-07T21:17:14+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107228",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107228"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107228"
        }
      ],
      "published": "2026-10-07T21:17:14+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107230",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        346,
        863
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107230"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107230"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107230"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107230"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107231",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522,
        757
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107231"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107231"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107231"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107231"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107280",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        1275
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107280"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107280"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107282",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        319,
        441,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107282"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107282"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107283",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        338
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12  and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107283"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107283"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-107285",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107285"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107285"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-13505",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD and scrypt parameter classes was zeroised on garbage collection by overriding Object.finalize. Finalization runs at an unspecified time and in an unspecified order and is serviced by a single finalizer thread, so where objects carrying a finalizer are allocated faster than that thread retires them the pending-finalization queue grows without bound: disposal falls arbitrarily far behind, which can contribute to an OutOfMemoryError under load, and the key material those objects hold stays resident in the heap for as long as they are queued, defeating the purpose of the zeroisation. The behaviour was not a problem on Java 8 or Java 11; it is later JVMs, on which finalization has been deprecated and progressively de-emphasised, where it becomes one. Disposal of these classes now runs from a java.lang.ref.Cleaner registered in the multi-release jdk1.9 overlay, so on Java 9 and later it no longer depends on the finalizer being scheduled. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected, as neither implements the finalizer-based zeroisation scheme.",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13505"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13505"
        },
        {
          "url": "https://github.com/advisories/GHSA-98j2-6v39-78w8"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9013505"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13505"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13505"
        }
      ],
      "published": "2026-08-08T02:17:16+00:00",
      "updated": "2026-09-03T16:44:20+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ]
    },
    {
      "id": "CVE-2026-13506",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        674
      ],
      "description": "In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13506"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13506"
        },
        {
          "url": "https://github.com/advisories/GHSA-qp49-qgx5-5m26"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13506"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13506"
        }
      ],
      "published": "2026-08-03T04:16:39+00:00",
      "updated": "2026-08-28T16:41:22+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ]
    },
    {
      "id": "CVE-2026-19032",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        470,
        610
      ],
      "description": "jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19032"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-19032"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6129"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19032"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19032"
        }
      ],
      "published": "2026-09-01T04:18:00+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-25680",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25680"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25680"
        },
        {
          "url": "https://go.dev/cl/781702"
        },
        {
          "url": "https://go.dev/issue/79573"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25680"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5028"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25680"
        }
      ],
      "published": "2026-05-22T16:16:19+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-25681",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1021
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69293"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25681"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41178"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55677"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69293.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69293"
        },
        {
          "url": "https://go.dev/cl/781703"
        },
        {
          "url": "https://go.dev/issue/79574"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-25681.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67139-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25681"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5029"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25681"
        }
      ],
      "published": "2026-05-22T16:16:19+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/net/html package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-27136",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1021
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27136"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69293"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27136"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41178"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55677"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69293.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69293"
        },
        {
          "url": "https://go.dev/cl/781685"
        },
        {
          "url": "https://go.dev/issue/79575"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-27136.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67139-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27136"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5030"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27136"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/net/html package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-27145",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        606
      ],
      "description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.",
      "recommendation": "Upgrade stdlib to version 1.25.11, 1.26.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27145"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29980"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33574"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36317"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42946"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49703"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49705"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49729"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49744"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49765"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51057"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52946"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53416"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54168"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54427"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54500"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54525"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54603"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55899"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57482"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59557"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59559"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59579"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59593"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60025"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60354"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60386"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68334"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68335"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27145"
        },
        {
          "url": "https://bugzilla.redhat.com/2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/2484207"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-36317.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36317"
        },
        {
          "url": "https://go.dev/cl/783621"
        },
        {
          "url": "https://go.dev/issue/79694"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-27145.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-53416.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5037"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27145"
        }
      ],
      "published": "2026-06-02T23:16:35+00:00",
      "updated": "2026-09-18T13:17:43+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-33117",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287,
        347
      ],
      "description": "The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.",
      "recommendation": "Upgrade com.azure:azure-security-keyvault-keys to version 4.10.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33117"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-33117"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/commit/1b5c5c79d85a5c9a9cfd07f6cdff6fd0f50eccf9"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/pull/48476"
        },
        {
          "url": "https://github.com/advisories/GHSA-97jf-46m3-8953"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33117"
        }
      ],
      "published": "2026-05-12T18:17:04+00:00",
      "updated": "2026-06-17T10:36:58+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3",
          "versions": [
            {
              "version": "4.10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3",
          "versions": [
            {
              "version": "4.10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "protected_by_mitigating_control",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product delegates key operations to the Azure Key Vault service (RSA-OAEP wrap/unwrap for envelope encryption); the vulnerable client-side local crypto path is not exercised, so the security-feature bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-33814",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835,
        606
      ],
      "description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.",
      "recommendation": "Upgrade golang.org/x/net to version 0.53.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33814"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22121"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56912"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57367"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57408"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57545"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60023"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60025"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60442"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60446"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60447"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60454"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60478"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62410"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62550"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62551"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63046"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63091"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63096"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63097"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63103"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63104"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63637"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63639"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66350"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33814"
        },
        {
          "url": "https://bugzilla.redhat.com/2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467810"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467811"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467823"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467825"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467826"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467827"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-22112.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:22121"
        },
        {
          "url": "https://github.com/golang/go/issues/78476"
        },
        {
          "url": "https://go-review.googlesource.com/c/go/+/761581"
        },
        {
          "url": "https://go-review.googlesource.com/c/net/+/761640"
        },
        {
          "url": "https://go.dev/cl/761581"
        },
        {
          "url": "https://go.dev/cl/761640"
        },
        {
          "url": "https://go.dev/issue/78476"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/qcCIEXso47M"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33814.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-22121.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4918"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8430-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8471-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8472-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8473-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33814"
        }
      ],
      "published": "2026-05-07T20:16:42+00:00",
      "updated": "2026-09-18T13:17:59+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33818.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0; Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59562"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60354"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61245"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63134"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-66432-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8883-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-09-17T12:18:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-39822",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        61
      ],
      "description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.",
      "recommendation": "Upgrade stdlib to version 1.25.12, 1.26.5, 1.27.0-rc.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39822"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38878"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39822"
        },
        {
          "url": "https://bugzilla.redhat.com/2498152"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498152"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-38878.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:38878"
        },
        {
          "url": "https://go.dev/cl/797880"
        },
        {
          "url": "https://go.dev/issue/79005"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39822.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-38995.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39822"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39822"
        }
      ],
      "published": "2026-07-08T17:17:21+00:00",
      "updated": "2026-09-17T17:10:20+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the Go stdlib flaw is carried by a bundled Go binary (the Confluent CLI / tooling) in the image, not the product's Java runtime, and it is not invoked with attacker-controlled input as part of the product, so the vulnerable code path is not reachable in the product."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.42.0",
          "versions": [
            {
              "version": "v0.42.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.42.0",
          "versions": [
            {
              "version": "v0.42.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.42.0",
          "versions": [
            {
              "version": "v0.42.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/sys@v0.42.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/sys@v0.42.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39827",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        924
      ],
      "description": "An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39827"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39827"
        },
        {
          "url": "https://go.dev/cl/781320"
        },
        {
          "url": "https://go.dev/issue/35127"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39827"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5016"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39827"
        }
      ],
      "published": "2026-05-22T04:16:21+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39828",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        295,
        281
      ],
      "description": "When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46903"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39828"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480687"
        },
        {
          "url": "https://go.dev/cl/781621"
        },
        {
          "url": "https://go.dev/issue/79562"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5014"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39828"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-11T13:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-39829",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        347,
        1284
      ],
      "description": "The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46903"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47949"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48693"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57801"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59559"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59593"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60446"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60454"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39829"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2493620"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493620"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37123.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37123"
        },
        {
          "url": "https://go.dev/cl/781641"
        },
        {
          "url": "https://go.dev/cl/781661"
        },
        {
          "url": "https://go.dev/issue/79565"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39829.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-37123.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5018"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39829"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-16T13:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-39830",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        119,
        772
      ],
      "description": "A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29455"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37278"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57801"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39830"
        },
        {
          "url": "https://bugzilla.redhat.com/2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69961.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69961"
        },
        {
          "url": "https://github.com/golang/crypto/commit/4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946"
        },
        {
          "url": "https://go.dev/cl/781640"
        },
        {
          "url": "https://go.dev/cl/781664"
        },
        {
          "url": "https://go.dev/issue/79564"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39830.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69961.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5017"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39830"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-16T13:17:53+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-39831",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        862
      ],
      "description": "The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39831"
        },
        {
          "url": "https://github.com/golang/crypto/commit/b61cf853a89d82cad68da5e12a6beca2116f8456"
        },
        {
          "url": "https://go.dev/cl/781662"
        },
        {
          "url": "https://go.dev/issue/79566"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39831"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39831"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "h2. Summary\n\nConfluent Platform's Alertmanager and Prometheus images carry this library version as an unused, transitive dependency. There is no exploitable code path for CVE-2026-39831 in these components today, so there is no immediate customer action required. As with the related CVE-2026-39830, Confluent will pick up the fix via a standard upstream version bump \u2014 the open-source Prometheus project already includes the fix starting at v3.13.0, and Alertmanager starting at v0.34.0 \u2014 in a future release.\n\nh2. Assessment Details\n\nh3. What is CVE-2026-39831?\n\nThis CVE affects the SSH module of a widely used open-source Go library, golang.org/x/crypto. It relates specifically to authentication using FIDO/U2F hardware security keys (the small USB/NFC devices some organizations use for extra-secure logins). Normally, using one of these keys to authenticate over SSH requires a physical touch on the device, confirming a real person is present. A flaw in the library's verification logic meant that, in certain conditions, a signature could be accepted without that physical touch actually happening, undermining the \"prove a human is present\" guarantee the hardware key is meant to provide.\n\nh3. Why doesn't this affect Confluent's Alertmanager and Prometheus images?\n\nJust like the related CVE-2026-39830, our scanning tools flagged this library in the cp-enterprise-alertmanager and cp-enterprise-prometheus images because it's pulled in indirectly, as a dependency of other libraries these components use for non-SSH purposes such as TLS networking support, not because either component performs SSH authentication. Neither Alertmanager nor Prometheus accepts SSH logins, uses SSH keys, or has any SSH server or client functionality anywhere in their code. Both communicate exclusively over HTTP (Alertmanager's API on port 9093, Prometheus's API on port 9090). Since this vulnerability is entirely about the SSH authentication handshake for hardware security keys, and neither program ever performs SSH authentication of any kind, the flawed code is never reached or executed.\n\nh3. How did we verify this?\n\nThis ticket shares the exact same affected package, versions, and codebases as CVE-2026-39830, which we already analyzed in depth. We confirmed the same conclusion applies here using the same two independent methods:\n\n# We used the Go build tooling directly to check whether the SSH module is needed by these programs at all, and it confirmed it is not required by either component.\n# We ran govulncheck, which builds a full call graph of each program and checks whether any code path actually reaches the vulnerable functions. It found no such path for this CVE in either component, while in the same scan correctly identifying and tracing dozens of other, unrelated vulnerabilities with concrete evidence of where they are actually called from.\n# We manually searched the source code of every affected version of both projects for any reference to the SSH module and found none outside of test code.\n\nAI-generated analysis. Reviewed and approved for customer sharing by a security engineer before use."
      }
    },
    {
      "id": "CVE-2026-39832",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502,
        281
      ],
      "description": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37410"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59579"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39832"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37410.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37410"
        },
        {
          "url": "https://github.com/golang/crypto/commit/e3d1254f1e7e60baa086142c46174bf6d8d0fe50"
        },
        {
          "url": "https://go.dev/cl/778640"
        },
        {
          "url": "https://go.dev/cl/778641"
        },
        {
          "url": "https://go.dev/cl/778642"
        },
        {
          "url": "https://go.dev/issue/79435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39832.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-37410.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5006"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39832"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-09-15T12:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh/agent package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-39833",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        862
      ],
      "description": "The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39833"
        },
        {
          "url": "https://github.com/golang/crypto/commit/0fb843a472225645e917c84f1f9744757f0bab14"
        },
        {
          "url": "https://go.dev/cl/778640"
        },
        {
          "url": "https://go.dev/cl/778641"
        },
        {
          "url": "https://go.dev/cl/778642"
        },
        {
          "url": "https://go.dev/issue/79436"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39833"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5005"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39833"
        }
      ],
      "published": "2026-05-22T04:16:22+00:00",
      "updated": "2026-08-11T22:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "h2. Summary\n\nConfluent Platform's Alertmanager and Prometheus images carry this library version as an unused, transitive dependency. There is no exploitable code path for CVE-2026-39833 in these components today, so there is no immediate customer action required. As with the related CVEs in this family, Confluent will pick up the fix via a standard upstream version bump \u2014 the open-source Prometheus project already includes the fix starting at v3.13.0, and Alertmanager starting at v0.34.0 \u2014 in a future release.\n\nh2. Assessment Details\n\nh3. What is CVE-2026-39833?\n\nThis CVE affects the SSH agent module of a widely used open-source Go library, golang.org/x/crypto. Some SSH keys held by an SSH agent can be configured to require confirmation before each use, so the agent is supposed to prompt for approval every time the key is used to sign something. A flaw in this library meant that constraint was silently ignored in some cases: the key would sign without ever prompting, even though it was configured to require confirmation.\n\nh3. Why doesn't this affect Confluent's Alertmanager and Prometheus images?\n\nAs with the related CVEs in this family, our scanning tools flagged this library in the cp-enterprise-alertmanager and cp-enterprise-prometheus images because it's pulled in indirectly, as a dependency of other libraries these components use for non-SSH purposes, not because either component uses SSH agents or SSH keys. Neither Alertmanager nor Prometheus manages SSH keys, talks to an SSH agent, or has any SSH functionality anywhere in their code. Both communicate exclusively over HTTP (Alertmanager's API on port 9093, Prometheus's API on port 9090). Since this vulnerability is entirely about SSH agent key-confirmation handling, and neither program ever performs SSH operations of any kind, the flawed code is never reached or executed.\n\nh3. How did we verify this?\n\nThis ticket shares the exact same affected package, versions, and codebases as the related tickets, which we already analyzed in depth:\n\n# We used the Go build tooling directly to check whether the SSH agent module is needed by these programs at all, and it confirmed it is not required by either component.\n# We ran govulncheck, which found no call path to this CVE's vulnerable function in either component, while correctly identifying and tracing dozens of other, unrelated vulnerabilities with concrete call evidence in the same scan.\n# We manually searched the source code of every affected version of both projects for any reference to the SSH module or its agent subpackage and found none outside of test code.\n\nAI-generated analysis. Reviewed and approved for customer sharing by a security engineer before use."
      }
    },
    {
      "id": "CVE-2026-39834",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39834"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39834"
        },
        {
          "url": "https://github.com/golang/crypto/commit/e052873987615dc96fe67607a9a6adb76311344f"
        },
        {
          "url": "https://go.dev/cl/781663"
        },
        {
          "url": "https://go.dev/issue/79567"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39834"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5020"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39834"
        }
      ],
      "published": "2026-05-22T04:16:24+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "h2. Summary\n\nConfluent Platform's Alertmanager and Prometheus images carry this library version as an unused, transitive dependency. There is no exploitable code path for CVE-2026-39834 in these components today, so there is no immediate customer action required. As with the related CVEs in this family, Confluent will pick up the fix via a standard upstream version bump \u2014 the open-source Prometheus project already includes the fix starting at v3.13.0, and Alertmanager starting at v0.34.0 \u2014 in a future release.\n\nh2. Assessment Details\n\nh3. What is CVE-2026-39834?\n\nThis CVE affects the SSH module of a widely used open-source Go library, golang.org/x/crypto. If a program uses this library to send a very large amount of data, more than 4 gigabytes, in a single write operation over an SSH connection, a bug in an internal size calculation could cause the sending logic to loop forever without making progress, effectively hanging that connection.\n\nh3. Why doesn't this affect Confluent's Alertmanager and Prometheus images?\n\nAs with the related CVEs in this family, our scanning tools flagged this library in the cp-enterprise-alertmanager and cp-enterprise-prometheus images because it's pulled in indirectly, as a dependency of other libraries these components use for non-SSH purposes. Neither Alertmanager nor Prometheus opens SSH connections or channels of any kind, both communicate exclusively over HTTP (Alertmanager's API on port 9093, Prometheus's API on port 9090). Since this vulnerability requires an active SSH channel write to trigger, and neither program ever creates one, the flawed code is never reached or executed.\n\nh3. How did we verify this?\n\nThis ticket shares the exact same affected package, versions, and codebases as the related tickets, which we already analyzed in depth:\n\n# We used the Go build tooling directly to check whether the SSH module is needed by these programs at all, and it confirmed it is not required by either component.\n# We ran govulncheck, which found no call path to this CVE's vulnerable functions in either component, while correctly identifying and tracing dozens of other, unrelated vulnerabilities with concrete call evidence in the same scan.\n# We manually searched the source code of every affected version of both projects for any reference to the SSH module and found none outside of test code.\n\nAI-generated analysis. Reviewed and approved for customer sharing by a security engineer before use."
      }
    },
    {
      "id": "CVE-2026-39835",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        295,
        476
      ],
      "description": "SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39835"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36199"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37272"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37296"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37410"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40969"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40972"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40974"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47949"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54525"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59593"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39835"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37410.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37410"
        },
        {
          "url": "https://go.dev/cl/781660"
        },
        {
          "url": "https://go.dev/issue/79563"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39835.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-38504.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5015"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39835"
        }
      ],
      "published": "2026-05-22T04:16:24+00:00",
      "updated": "2026-09-18T13:18:12+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-39882",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        789
      ],
      "description": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0.",
      "recommendation": "Upgrade go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to version 1.43.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39882"
        },
        {
          "url": "http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39882"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/pull/8108"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39882"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39882"
        }
      ],
      "published": "2026-04-08T21:17:00+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39883",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        426
      ],
      "description": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.",
      "recommendation": "Upgrade go.opentelemetry.io/otel/sdk to version 1.43.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39883"
        },
        {
          "url": "http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26254"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26257"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456718"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39883"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39883.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39883"
        }
      ],
      "published": "2026-04-08T21:17:00+00:00",
      "updated": "2026-09-09T13:19:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "This issue only affects BSD / Solaris deployments with kenv."
      }
    },
    {
      "id": "CVE-2026-40984",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nmicrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.\nmicrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.\nmicrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.",
      "recommendation": "Upgrade io.micrometer:micrometer-core to version 1.16.6, 1.15.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40984"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40984"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-40984"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486716"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer/commit/36da131525228188a36779a28471a76c79213dd4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40984"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json"
        },
        {
          "url": "https://spring.io/security/cve-2026-40984"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40984"
        }
      ],
      "published": "2026-06-09T05:16:34+00:00",
      "updated": "2026-09-14T13:18:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.micrometer/micrometer-core@1.14.4",
          "versions": [
            {
              "version": "1.14.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.micrometer/micrometer-core@1.14.4",
          "versions": [
            {
              "version": "1.14.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The vulnerable micrometer-core HTTP-method-tagging classes are present transitively via Armeria but are never invoked, since Control-Center never wires Armeria's metrics decorators and its actual REST server carries no micrometer dependency at all."
      }
    },
    {
      "id": "CVE-2026-42502",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1021
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69293"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42502"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/2493622"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484830"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493622"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41178"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55677"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69293.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69293"
        },
        {
          "url": "https://go.dev/cl/781701"
        },
        {
          "url": "https://go.dev/issue/79572"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67139-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42502"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5027"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42502"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42504",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.",
      "recommendation": "Upgrade stdlib to version 1.25.11, 1.26.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42504"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42504"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/774481"
        },
        {
          "url": "https://go.dev/issue/79217"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42504.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69308.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42504"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42504"
        }
      ],
      "published": "2026-06-02T23:16:37+00:00",
      "updated": "2026-07-22T19:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-42505",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        201
      ],
      "description": "Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",
      "recommendation": "Upgrade stdlib to version 1.25.12, 1.26.5, 1.27.0-rc.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42505"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66364"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42505"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-66364.html"
        },
        {
          "url": "https://go.dev/cl/775960"
        },
        {
          "url": "https://go.dev/issue/79282"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5856"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42505"
        }
      ],
      "published": "2026-07-08T17:17:21+00:00",
      "updated": "2026-09-16T20:14:44+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the Go stdlib flaw is carried by a bundled Go binary (the Confluent CLI / tooling) in the image, not the product's Java runtime, so the vulnerable code path is not reachable in the product."
      }
    },
    {
      "id": "CVE-2026-42506",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.",
      "recommendation": "Upgrade golang.org/x/net to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42506"
        },
        {
          "url": "https://go.dev/cl/781700"
        },
        {
          "url": "https://go.dev/issue/79571"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42506"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5025"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42506"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42507",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "description": "When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.",
      "recommendation": "Upgrade stdlib to version 1.25.11, 1.26.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42507"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66364"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42507"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484205"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42507"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-66364.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:29981"
        },
        {
          "url": "https://go.dev/cl/777060"
        },
        {
          "url": "https://go.dev/issue/79346"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42507.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-29981.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42507"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5039"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42507"
        }
      ],
      "published": "2026-06-02T23:16:38+00:00",
      "updated": "2026-07-22T19:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42508",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35833"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37123"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49944"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51288"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52910"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42508"
        },
        {
          "url": "https://bugzilla.redhat.com/2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/2493620"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480680"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480681"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480685"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480688"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480761"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493620"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37123.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37123"
        },
        {
          "url": "https://github.com/golang/crypto/commit/f717e29698a271c548239ed56bf5dd9516d6f7e8"
        },
        {
          "url": "https://go.dev/cl/781220"
        },
        {
          "url": "https://go.dev/issue/79568"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42508.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-37123.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5021"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42508"
        }
      ],
      "published": "2026-05-22T04:16:25+00:00",
      "updated": "2026-09-15T12:17:45+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh package is not compiled into either bundled Prometheus or Alertmanager binary."
      }
    },
    {
      "id": "CVE-2026-44249",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284,
        697,
        1287
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44249"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48124"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49700"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49701"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44249"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-44249"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488081"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44249"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44249"
        }
      ],
      "published": "2026-06-11T22:16:56+00:00",
      "updated": "2026-09-18T13:18:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. netty's IP subnet filter (IpSubnetFilterRule / IpFilterRule) is not used anywhere in the product, so the IPv6 comparator-masking bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-45292",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.",
      "recommendation": "Upgrade io.opentelemetry:opentelemetry-api to version 1.62.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45292"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45292"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45292"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482785"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/commit/03837d3c1763bc35464aea1078671e2ef2336a5f"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/pull/8380"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/releases/tag/v1.62.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/security/advisories/GHSA-rcgg-9c38-7xpx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45292"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
        }
      ],
      "published": "2026-05-28T17:16:32+00:00",
      "updated": "2026-09-10T13:20:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1",
          "versions": [
            {
              "version": "1.42.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1",
          "versions": [
            {
              "version": "1.42.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the OpenTelemetry W3C Baggage propagator is not wired to parse inbound request headers, so the unbounded baggage-allocation path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45416",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45416"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49700"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49701"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45416"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45416"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488391"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45416"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45416"
        }
      ],
      "published": "2026-06-12T15:16:26+00:00",
      "updated": "2026-09-18T13:18:25+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. netty's SniHandler is not wired on any listener in this product, so the vulnerable ClientHello buffer pre-allocation path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45536",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        200,
        772
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) \u2014 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking \u2192 EAGAIN \u2192 Java maps to 0 \u2192 read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-transport-native-epoll to version 4.2.15.Final, 4.1.135.Final; Upgrade io.netty:netty-transport-native-kqueue to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45536"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45536"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45536"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-w573-9ffj-6ff9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45536"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45536"
        }
      ],
      "published": "2026-06-12T15:16:27+00:00",
      "updated": "2026-06-17T10:52:10+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-epoll@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-kqueue@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-kqueue@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-kqueue@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-epoll@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-kqueue@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-epoll@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-kqueue@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-kqueue@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-native-epoll@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-transport-native-epoll@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-transport-native-kqueue@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-transport-native-kqueue@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-transport-native-epoll@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-transport-native-epoll@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-transport-native-kqueue@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-transport-native-kqueue@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-transport-native-epoll@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not use netty's native epoll/kqueue Unix-domain-socket transport for file-descriptor passing, so the vulnerable dual-fd receive path is not reachable (the flaw is also local-only, AV:L)."
      }
    },
    {
      "id": "CVE-2026-45673",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        330,
        340
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-resolver-dns to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45673"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45673"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45673"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-xmv7-r254-6q78"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45673"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45673"
        }
      ],
      "published": "2026-06-12T15:16:27+00:00",
      "updated": "2026-06-17T10:52:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. netty's DNS resolver (DnsAddressResolverGroup / DnsNameResolver) is never instantiated; name resolution uses the JVM resolver, so the vulnerable path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45674",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        345,
        346
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-resolver-dns to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49700"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49701"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53806"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45674"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45674"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488400"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45674"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45674.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45674"
        }
      ],
      "published": "2026-06-12T15:16:27+00:00",
      "updated": "2026-09-18T13:18:26+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. netty's DNS resolver (DnsAddressResolverGroup / DnsNameResolver) is never instantiated; name resolution uses the JVM resolver, so the vulnerable CNAME bailiwick path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45799",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.",
      "recommendation": "Upgrade com.squareup.wire:wire-runtime-jvm to version 6.3.0, 7.0.0-alpha03",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45799"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45799"
        },
        {
          "url": "https://github.com/square/wire"
        },
        {
          "url": "https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0"
        },
        {
          "url": "https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773"
        },
        {
          "url": "https://github.com/square/wire/pull/3595"
        },
        {
          "url": "https://github.com/square/wire/pull/3597"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/6.3.0"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/7.0.0-alpha03"
        },
        {
          "url": "https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45799"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45799"
        }
      ],
      "published": "2026-07-17T20:17:18+00:00",
      "updated": "2026-08-12T19:04:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0",
          "versions": [
            {
              "version": "5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0",
          "versions": [
            {
              "version": "5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-46595",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        863,
        303
      ],
      "description": "Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61314"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480689"
        },
        {
          "url": "https://github.com/golang/crypto/commit/533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce"
        },
        {
          "url": "https://go.dev/cl/781642"
        },
        {
          "url": "https://go.dev/issue/79570"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5023"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8447-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46595"
        }
      ],
      "published": "2026-05-22T04:16:25+00:00",
      "updated": "2026-09-11T13:18:12+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The golang.org/x/crypto/ssh package is not compiled into either bundled Prometheus or Alertmanager binary, despite this CVE's CVSS 10.0 upstream severity."
      }
    },
    {
      "id": "CVE-2026-46597",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        704
      ],
      "description": "An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46597"
        },
        {
          "url": "https://go.dev/cl/781620"
        },
        {
          "url": "https://go.dev/issue/79561"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46597"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46597"
        }
      ],
      "published": "2026-05-22T04:16:26+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46598",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        129
      ],
      "description": "For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.52.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46598"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46598"
        },
        {
          "url": "https://go.dev/cl/781360"
        },
        {
          "url": "https://go.dev/issue/79596"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/a082jnz-LvI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46598"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5033"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46598"
        }
      ],
      "published": "2026-05-22T04:16:26+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade golang.org/x/net to version 0.56.0; Upgrade stdlib to version 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-47244",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-47244"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-47244"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-47244"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47244"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47244"
        }
      ],
      "published": "2026-06-12T15:16:29+00:00",
      "updated": "2026-06-17T10:54:25+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-facing netty HTTP/2 server is wired in a standard deployment (the ce-kafka netty HTTP/2 path is Confluent Cloud proxy / cluster-link client infrastructure gated by proxy-protocol config; ksqlDB's Vert.x server defaults maxConcurrentStreams=100), so the unbounded-streams DoS is not reachable."
      }
    },
    {
      "id": "CVE-2026-47691",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        345,
        346
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-resolver-dns to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-47691"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49700"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49701"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53806"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-47691"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-47691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488439"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-5pvg-856g-cp85"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47691"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47691.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8742-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47691"
        }
      ],
      "published": "2026-06-12T16:16:30+00:00",
      "updated": "2026-09-18T13:18:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-resolver-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-resolver-dns@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. netty's DNS resolver (DnsAddressResolverGroup / DnsNameResolver) is never instantiated; name resolution uses the JVM resolver, so the vulnerable NS-record path is not reachable."
      }
    },
    {
      "id": "CVE-2026-48043",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        401,
        772
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.1.135.Final, 4.2.15.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-48043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48124"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53806"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-48043"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-48043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488442"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/3d45a1e4e8eb99144f716e54be5ac57e525fa7ca"
        },
        {
          "url": "https://github.com/netty/netty/commit/db6138b168699736a6463c367e12ad0a4c36a25e"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48043"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48043"
        }
      ],
      "published": "2026-06-12T16:16:30+00:00",
      "updated": "2026-09-18T13:18:30+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-facing netty HTTP/2 server with gzip decompression is wired in a standard deployment (netty HTTP/2 is Confluent Cloud proxy / cluster-link infrastructure), so the refcount-leak memory-exhaustion path is not reachable."
      }
    },
    {
      "id": "CVE-2026-49844",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        116
      ],
      "description": "Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.",
      "recommendation": "Upgrade org.apache.logging.log4j:log4j-api to version 2.25.5, 2.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49844"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49844"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-49844"
        },
        {
          "url": "https://github.com/apache/logging-log4j2"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/pull/4163"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"
        },
        {
          "url": "https://logging.apache.org/cyclonedx/vdr.xml"
        },
        {
          "url": "https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message"
        },
        {
          "url": "https://logging.apache.org/security.html#CVE-2026-49844"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49844"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
        }
      ],
      "published": "2026-07-10T22:16:42+00:00",
      "updated": "2026-07-14T20:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4",
          "versions": [
            {
              "version": "2.25.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4",
          "versions": [
            {
              "version": "2.25.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves log4j-api live to the fixed 2.25.5 and the MapMessage/JsonTemplateLayout sink is absent from its source anyway, while control-center-fe has no log4j dependency at all as it is pure JS/TS."
      }
    },
    {
      "id": "CVE-2026-50010",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26017"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34608"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49700"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49701"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50085"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53645"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50010"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-50010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488429"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50010"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50010"
        }
      ],
      "published": "2026-06-12T16:16:31+00:00",
      "updated": "2026-09-18T13:18:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. TLS hostname verification is enforced through the JSSE endpoint-identification algorithm (HTTPS) on the SSLEngine/SSLParameters, not through netty's trust-manager wrapping, so the silent hostname-verification-bypass path is not reached."
      }
    },
    {
      "id": "CVE-2026-50020",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00\u20130x1F and 0x7F) as well as all whitespace. RFC 9112 \u00a72.2 only asks servers to ignore empty CRLF lines preceding the request-line \u2014 a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50020"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50020"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-50020"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50020"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50020"
        }
      ],
      "published": "2026-06-12T16:16:31+00:00",
      "updated": "2026-06-17T10:57:35+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product's HTTP endpoints do not wire netty's HttpObjectDecoder / HttpServerCodec (Jetty is used), so the vulnerable decoder path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50560",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.15.Final, 4.1.135.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50560"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50560"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-50560"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50560"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50560"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"
        }
      ],
      "published": "2026-06-12T16:16:32+00:00",
      "updated": "2026-06-17T10:57:42+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no netty HTTP/2 codec (Http2FrameCodec / Http2ConnectionHandler) is wired on any listener, so the vulnerable path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54399",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser\u00a0in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows\u00a0an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54399"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54399"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"
        },
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54399"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
        }
      ],
      "published": "2026-07-01T17:16:36+00:00",
      "updated": "2026-07-24T20:04:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.3",
          "versions": [
            {
              "version": "5.3.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.3",
          "versions": [
            {
              "version": "5.3.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.3"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54428",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5-h2 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54428"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54428"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54428"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"
        },
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54428"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
        }
      ],
      "published": "2026-07-01T18:16:34+00:00",
      "updated": "2026-07-24T20:03:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54512",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        184,
        502
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container \u2014 for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 3.1.4, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54512"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54512"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-40895.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:40895"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5%20%28jackson-databind-2.18.8%29"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5988"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54512.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T21:01:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The control-center-backend uses only a single name-based @JsonTypeInfo site and the frontend has none, so no untrusted JSON is deserialized via class-name resolution and the PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54513",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54513"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43218"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44062"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44065"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48095"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62260"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66488"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54513"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54513"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-40895.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:40895"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5981"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5983"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5984"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54513.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-09-14T13:18:40+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not enable class-based polymorphic deserialization (default typing, or @JsonTypeInfo with Id.CLASS/Id.MINIMAL_CLASS) on untrusted input, so the array-subtype PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54514",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        918
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54514"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54514"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54514"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5951"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-controlled JSON is deserialized into a java.net.InetSocketAddress (the type appears only in networking code, not bound via jackson), so the eager-DNS-resolution SSRF path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54515",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map \u2014 restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 3.1.4, 2.18.9, 2.21.5, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54515"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54515"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5964"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-29T13:38:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. MapperFeature.ACCEPT_CASE_INSENSITIVE_PROPERTIES is not enabled in the product, so the case-insensitive @JsonIgnoreProperties bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54516",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty(\"renamed\") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; during deserialization BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a FieldProperty, and makes the backing field writable. An attacker supplying the renamed JSON key writes the backing field directly, bypassing the @JsonIgnore on the setter. This vulnerability is fixed in 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54516"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54516"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54516"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5967"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5968"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-9fxm-vc8v-hj55"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54516"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54516"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:52:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No DTO anywhere in the codebase uses the @JsonIgnore-plus-renamed-setter pattern this CVE targets; the annotation is only ever used for response shaping, never as a deserialization security boundary."
      }
    },
    {
      "id": "CVE-2026-54517",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54517"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54517"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54517"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5969"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5970"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54517"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54517"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:51:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. @JsonView is never used anywhere in control-center-backend, so there is no view-based access-control boundary for this CVE's bypass to defeat."
      }
    },
    {
      "id": "CVE-2026-54518",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54518"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54518"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54518"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5971"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5973"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rcqc-6cw3-h962"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54518"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54518"
        }
      ],
      "published": "2026-06-23T22:16:32+00:00",
      "updated": "2026-06-27T20:49:30+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. @JsonView is never used anywhere in control-center-backend, so there is no view-based access-control boundary for this CVE's bypass to defeat."
      }
    },
    {
      "id": "CVE-2026-55688",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1275
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.11, 2.16.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55688"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55688"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-55688"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e6955c1e3951cf80e286981d064f6c926ce33f47"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2196"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2199"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.0"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.11"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"
        },
        {
          "url": "https://github.com/advisories/GHSA-m452-q8c9-rg2f"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55688"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8655-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55688"
        }
      ],
      "published": "2026-07-01T20:17:11+00:00",
      "updated": "2026-08-06T22:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-55831",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55831"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-55831"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55831"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55831"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T15:17:16+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final via netty-codec-http2 and async-http-client, has no direct usage of any SPDY-related classes, and runs no Netty-based server of its own."
      }
    },
    {
      "id": "CVE-2026-55833",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55833"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-55833"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55833"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55833"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T13:34:45+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final via netty-codec-http2 and async-http-client, has no direct usage of any SPDY-related classes, and runs no Netty-based server of its own."
      }
    },
    {
      "id": "CVE-2026-56745",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56745"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56745"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56745"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56745"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56745"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:46:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final via netty-codec-http2 and async-http-client, has no direct usage of any SPDY-related classes, and runs no Netty-based server of its own."
      }
    },
    {
      "id": "CVE-2026-56746",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        284
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56746"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56746"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56746"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56746"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56746"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:47:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final and has no direct usage of CorsHandler anywhere in its source."
      }
    },
    {
      "id": "CVE-2026-56819",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        401
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56819"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56819"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56819"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bhttps://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56819"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56819"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:46:35+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http2 to the fixed 4.1.136.Final directly at compile scope, has no direct usage of Http2ConnectionHandler or Http2FrameCodec, and runs no Netty-based server of its own."
      }
    },
    {
      "id": "CVE-2026-56851",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        787
      ],
      "description": "The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.",
      "recommendation": "Upgrade golang.org/x/text to version 0.41.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56851"
        },
        {
          "url": "https://go.dev/cl/793360"
        },
        {
          "url": "https://go.dev/issue/80112"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6629"
        }
      ],
      "published": "2026-10-07T18:17:20+00:00",
      "updated": "2026-10-08T21:35:53+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/text@v0.35.0",
          "versions": [
            {
              "version": "v0.35.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.35.0",
          "versions": [
            {
              "version": "v0.35.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.37.0",
          "versions": [
            {
              "version": "v0.37.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.37.0",
          "versions": [
            {
              "version": "v0.37.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.35.0",
          "versions": [
            {
              "version": "v0.35.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.37.0",
          "versions": [
            {
              "version": "v0.37.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/text@v0.35.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/text@v0.37.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/text@v0.35.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/text@v0.37.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56852",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        835
      ],
      "description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.",
      "recommendation": "Upgrade golang.org/x/text to version 0.39.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70201"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56852"
        },
        {
          "url": "https://bugzilla.redhat.com/2456335"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2504233"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504233"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33810"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56852"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-70201.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70201"
        },
        {
          "url": "https://go.dev/cl/794100"
        },
        {
          "url": "https://go.dev/issue/80142"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56852.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70201.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56852"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56852"
        }
      ],
      "published": "2026-07-21T20:17:02+00:00",
      "updated": "2026-07-23T18:27:48+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/text@v0.35.0",
          "versions": [
            {
              "version": "v0.35.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.35.0",
          "versions": [
            {
              "version": "v0.35.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.37.0",
          "versions": [
            {
              "version": "v0.37.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.37.0",
          "versions": [
            {
              "version": "v0.37.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.35.0",
          "versions": [
            {
              "version": "v0.35.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.37.0",
          "versions": [
            {
              "version": "v0.37.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/text@v0.35.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/text@v0.37.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/text@v0.35.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/text@v0.37.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56853.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56854",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56854"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56854"
        },
        {
          "url": "https://go.dev/cl/797040"
        },
        {
          "url": "https://go.dev/issue/80213"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6303"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56854"
        }
      ],
      "published": "2026-08-28T16:18:17+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56855",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70640"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56855"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503742"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528050"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15789"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56855"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70640.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70640"
        },
        {
          "url": "https://go.dev/cl/826524"
        },
        {
          "url": "https://go.dev/issue/81317"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/1y3fb2np35U"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56855.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70640.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6355"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56855"
        }
      ],
      "published": "2026-09-02T20:17:36+00:00",
      "updated": "2026-09-04T16:34:56+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56857",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56857"
        },
        {
          "url": "https://go.dev/cl/847305"
        },
        {
          "url": "https://go.dev/issue/81739"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6604"
        }
      ],
      "published": "2026-10-08T23:17:01+00:00",
      "updated": "2026-10-08T23:17:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56858.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://bugzilla.redhat.com/2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69961.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69961"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56859.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70201.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56860.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56862.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56866",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56866"
        },
        {
          "url": "https://go.dev/cl/847306"
        },
        {
          "url": "https://go.dev/issue/81740"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6605"
        }
      ],
      "published": "2026-10-08T23:17:01+00:00",
      "updated": "2026-10-08T23:17:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-59888",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59888"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59888"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59888"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5974"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59888"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
        }
      ],
      "published": "2026-07-14T17:17:15+00:00",
      "updated": "2026-07-15T20:18:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59889",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.5, 2.18.9, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59889"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59889"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59889"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6060"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6056"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59889"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59889"
        }
      ],
      "published": "2026-07-14T21:17:06+00:00",
      "updated": "2026-07-16T16:19:15+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. @JsonView is never used anywhere in control-center-backend, so there is no view-based access-control boundary for this CVE's bypass to defeat."
      }
    },
    {
      "id": "CVE-2026-59898",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59898"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59898"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59898"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59898"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59898"
        }
      ],
      "published": "2026-07-29T19:16:48+00:00",
      "updated": "2026-08-06T20:35:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final and does not implement a WebSocket server using WebSocketServerHandshaker07/08."
      }
    },
    {
      "id": "CVE-2026-59899",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59899"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59899"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59899"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"
        },
        {
          "url": "https://netty.io/news/2026/07/09/4-1-136-Final.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59899"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59899"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:25:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final and has no server-side content-encoding pipeline that would invoke HttpContentEncoder."
      }
    },
    {
      "id": "CVE-2026-59900",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59900"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59900"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59900"
        },
        {
          "url": "https://github.com/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59900"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59900"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http2@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http2 to the fixed 4.1.136.Final directly at compile scope, has no direct usage of Http2ConnectionHandler or Http2FrameCodec, and runs no Netty-based server of its own."
      }
    },
    {
      "id": "CVE-2026-59901",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec to version 4.1.136.Final; Upgrade io.netty:netty-codec-compression to version 4.2.16.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59901"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59901"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59901"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59901"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59901"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-compression@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-compression@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-compression@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-compression@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. netty-codec-compression is not resolved anywhere in control-center-backend's dependency graph in any module or scope, and a source-wide search for Bzip2Decoder returns zero matches."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59903"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59903"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59903"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-09-23T15:21:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ]
    },
    {
      "id": "CVE-2026-59921",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59921"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59921"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59921"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59921"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59921"
        }
      ],
      "published": "2026-07-28T23:17:09+00:00",
      "updated": "2026-08-07T15:05:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-http@4.1.133.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-http to the fixed 4.1.136.Final and never uses HttpPostRequestEncoder to build multipart requests anywhere in its source."
      }
    },
    {
      "id": "CVE-2026-59949",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59949"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59949"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59949"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59949"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59949"
        }
      ],
      "published": "2026-08-18T15:16:56+00:00",
      "updated": "2026-09-18T20:09:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The backend reaches lz4-java only transitively via kafka-clients' own bounds-checked LZ4 codec, which never calls the vulnerable streaming XXHash API, and the frontend has no Java or lz4-java dependency at all."
      }
    },
    {
      "id": "CVE-2026-64607",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message.\u00a0Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "recommendation": "Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-64607"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-64607"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-64607"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1"
        },
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64607"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64607"
        }
      ],
      "published": "2026-07-31T11:17:11+00:00",
      "updated": "2026-08-13T17:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-68494",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08).",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-68494"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-68494"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-68494"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1611"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"
        },
        {
          "url": "https://github.com/advisories/GHSA-72hv-8253-57qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68494"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18401"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68494"
        }
      ],
      "published": "2026-08-04T15:16:41+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-68497",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-68497"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-68497"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-68497"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6127"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-68497.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77648.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68497"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68497"
        }
      ],
      "published": "2026-09-11T16:17:39+00:00",
      "updated": "2026-09-18T19:34:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-73508",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-dns to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73508"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-73508"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-73508"
        },
        {
          "url": "https://github.com/advisories/GHSA-mfg7-5gfp-c4w3"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73508"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-09-23T15:39:29+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-codec-dns@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-dns@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-codec-dns@4.2.13.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. control-center-backend already resolves netty-codec-dns to the fixed 4.1.136.Final and uses it only for outbound client-side DNS resolution via netty-resolver-dns, with no direct usage of DnsRecordDecoder."
      }
    },
    {
      "id": "CVE-2026-75595",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75595"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75595"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-75595"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75595"
        }
      ],
      "published": "2026-08-19T21:17:37+00:00",
      "updated": "2026-09-22T19:33:26+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        }
      ]
    },
    {
      "id": "CVE-2026-75596",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75596"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-75596"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75596"
        }
      ],
      "published": "2026-08-19T21:17:37+00:00",
      "updated": "2026-09-22T19:28:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.133.Final",
          "versions": [
            {
              "version": "4.1.133.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.13.Final",
          "versions": [
            {
              "version": "4.2.13.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.1.133.Final"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/io.netty/netty-handler@4.2.13.Final"
        }
      ]
    },
    {
      "id": "CVE-2026-77310",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        918
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.9, 2.21.5, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77310"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77310"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77310"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6058"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77310"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77310"
        }
      ],
      "published": "2026-08-24T20:17:20+00:00",
      "updated": "2026-09-09T21:06:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-78659",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.",
      "recommendation": "Upgrade golang.org/x/net to version 0.60.0; Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78659"
        },
        {
          "url": "https://go.dev/cl/847185"
        },
        {
          "url": "https://go.dev/cl/847314"
        },
        {
          "url": "https://go.dev/issue/81857"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6603"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-78660",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.",
      "recommendation": "Upgrade golang.org/x/net to version 0.60.0; Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78660"
        },
        {
          "url": "https://go.dev/cl/835145"
        },
        {
          "url": "https://go.dev/cl/836385"
        },
        {
          "url": "https://go.dev/issue/81115"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6610"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-78662",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78662"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78662"
        },
        {
          "url": "https://go.dev/cl/826504"
        },
        {
          "url": "https://go.dev/issue/81316"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/1y3fb2np35U"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6354"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78662"
        }
      ],
      "published": "2026-09-02T20:17:37+00:00",
      "updated": "2026-09-04T16:33:34+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ]
    },
    {
      "id": "CVE-2026-78663",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.",
      "recommendation": "Upgrade golang.org/x/net to version 0.60.0; Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78663"
        },
        {
          "url": "https://go.dev/cl/847187"
        },
        {
          "url": "https://go.dev/cl/847310"
        },
        {
          "url": "https://go.dev/issue/81743"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6612"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-78667",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78667"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78667"
        },
        {
          "url": "https://go.dev/cl/847309"
        },
        {
          "url": "https://go.dev/issue/81858"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78667"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6609"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78667"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-78669",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.",
      "recommendation": "Upgrade golang.org/x/net to version 0.60.0; Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78669"
        },
        {
          "url": "https://go.dev/cl/847186"
        },
        {
          "url": "https://go.dev/cl/847308"
        },
        {
          "url": "https://go.dev/issue/81742"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6611"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-81870",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        200,
        532
      ],
      "description": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0.",
      "recommendation": "Upgrade go.opentelemetry.io/otel/exporters/otlp/otlptrace to version 1.45.0; Upgrade go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc to version 1.45.0; Upgrade go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to version 1.45.0; Upgrade go.opentelemetry.io/otel/sdk to version 1.45.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-81870"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-81870"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/pull/8438"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81870"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-81870"
        }
      ],
      "published": "2026-09-16T20:17:32+00:00",
      "updated": "2026-09-30T17:51:56+00:00",
      "affects": [
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.44.0",
          "versions": [
            {
              "version": "v1.44.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.41.0",
          "versions": [
            {
              "version": "v1.41.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/sdk@v1.44.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.44.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.44.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.41.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.44.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.41.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.41.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/go.opentelemetry.io/otel/sdk@v1.41.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.41.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.41.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/go.opentelemetry.io/otel/sdk@v1.44.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.44.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.44.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.44.0"
        }
      ]
    },
    {
      "id": "CVE-2026-83557",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        502,
        915
      ],
      "description": "DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-83557"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-83557"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-83557"
        },
        {
          "url": "https://getsafety.com/vulnerabilities/SFTY-20260901-46895/CVE-2026-83557"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6156"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6155"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83557"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-83557"
        }
      ],
      "published": "2026-09-01T15:17:37+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-84303",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [],
      "cwes": [
        178,
        863
      ],
      "description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.83.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84303"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9332"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9335"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.1"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        }
      ],
      "published": "2026-09-01T19:17:30+00:00",
      "updated": "2026-09-09T21:09:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        }
      ]
    },
    {
      "id": "CVE-2026-84304",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.83.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84304"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84304"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9331"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9333"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.1"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84304"
        }
      ],
      "published": "2026-09-01T19:17:30+00:00",
      "updated": "2026-09-09T21:09:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        }
      ]
    },
    {
      "id": "CVE-2026-84445",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        129,
        248
      ],
      "description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84445"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76744"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84445"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533175"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84445"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76744"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f"
        },
        {
          "url": "https://github.com/grpc/grpc-go/issues/9354"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9365"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9366"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9367"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.82.2"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.2"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84445"
        }
      ],
      "published": "2026-09-14T17:17:51+00:00",
      "updated": "2026-09-25T14:10:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        }
      ]
    },
    {
      "id": "CVE-2026-85716",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        287,
        390
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and still deliver the response as authenticated. On a non-TLS or compromised transport, a peer that has not proved knowledge of the shared secret can therefore be accepted as the server. The fix rejects a present invalid value and computes Digest rspauth from the Authorization parameters actually sent, but verification remains unenforced when the value is absent, the sent parameters cannot be recovered, or Digest uses qop=auth-int. This issue is fixed in version 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85716"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-85716"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2235"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fj9w-c36g-h5x8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85716"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85716"
        }
      ],
      "published": "2026-09-17T17:16:50+00:00",
      "updated": "2026-09-24T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-85717",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        200,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85717"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85717"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/43db7bba81430cbd61ec2dc2c7be464e0ff6a0ff"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/b66757bec34def2e9867bb2b77bd848b1112abb4"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2224"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f8m2-889x-vw4x"
        },
        {
          "url": "https://github.com/advisories/GHSA-f8m2-889x-vw4x"
        }
      ],
      "published": "2026-09-17T16:18:15+00:00",
      "updated": "2026-09-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-85720",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and NettyRequestSender.sendRequestWithNewChannel attach Authorization to the plaintext CONNECT request before the TLS tunnel exists. Basic or Digest credentials and per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin are therefore visible to the proxy and to observers on the client-to-proxy hop. The tunneled request still receives origin Authorization after the tunnel is established, while Proxy-Authorization remains on CONNECT for its intended proxy recipient. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85720"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85720"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/9dba5ac988b7e750551f59b2eab550b60ac8a0d6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d07dbc79f5cf378f63c246f6101d7579ace55acc"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2234"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-xr57-gcx8-52hf"
        },
        {
          "url": "https://github.com/advisories/GHSA-xr57-gcx8-52hf"
        }
      ],
      "published": "2026-09-17T17:16:51+00:00",
      "updated": "2026-09-24T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-85721",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        409
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a cumulative output-size limit. A hostile or compromised server, or an attacker who can alter a response in transit, can send a small gzip, deflate, or snappy response that expands across chunks until the client exhausts its heap and raises OutOfMemoryError; brotli and zstd are also affected when their optional codecs are present. In versions 3.0.8 through 3.0.10, the HTTP/2 decompressor is also unbounded, so switching protocols does not mitigate the issue on those releases. A limit applied to each decode call is insufficient because the response can be delivered as many small chunks, so the fixed implementation tracks total decompressed bytes for the whole response. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85721"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-85721"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85721"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/5ee2841cbf268bba4a200578be3938ccfc6cc6d6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/663a1a91757904b22cfe37e2e6049f1f8ea6ae59"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e1871a19972fb496be1b8ac6be11d79e22ff2162"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e9f2f7423e0f6503f529656f2955a1317e56ba14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-7grg-jcf7-rpmx"
        },
        {
          "url": "https://github.com/advisories/GHSA-7grg-jcf7-rpmx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85721"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85721"
        }
      ],
      "published": "2026-09-17T16:18:16+00:00",
      "updated": "2026-09-30T17:43:24+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ]
    },
    {
      "id": "CVE-2026-8763",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295
      ],
      "description": "In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8763"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8763"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-8763"
        },
        {
          "url": "https://github.com/advisories/GHSA-9pwp-9qqc-pr26"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558"
        },
        {
          "url": "https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2026-8763"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8763"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8763"
        }
      ],
      "published": "2026-08-03T01:16:45+00:00",
      "updated": "2026-09-02T14:28:48+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ]
    },
    {
      "id": "CVE-2026-8798",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        835
      ],
      "description": "In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failure through their carry flag, and the JNI seeding routine spun re-issuing the instruction for as long as that flag stayed clear, so a persistent failure of the on-chip entropy source - whether from a hardware fault, from the underlying DRBG being exhausted by contention across many cores, or from a hypervisor that does not provide the instruction - left the calling thread looping indefinitely inside the JNI call, where it could be neither interrupted nor timed out. Any operation drawing from the native entropy source could therefore hang, denying service to the application. The retry loops are now bounded (200 attempts for RDSEED and 20 for RDRAND, twice the baselines given in Intel's Digital Random Number Generator software implementation guide), pausing between attempts and, on exhaustion, clearing any partially written buffer and throwing rather than continuing to spin. The clear is performed by an un-elidable memzero, which uses a volatile pointer and an assembly memory barrier so that a compiler cannot optimise the erase away as a dead store. Bouncy Castle for Java (bcprov) is not affected, as it has no native entropy source; the 1.0.X and 2.0.X FIPS series are not affected.",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8798"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-8798"
        },
        {
          "url": "https://github.com/advisories/GHSA-v6w3-qrh8-qccc"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908798"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8798"
        }
      ],
      "published": "2026-08-08T01:16:31+00:00",
      "updated": "2026-09-03T16:44:20+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ]
    },
    {
      "id": "CVE-2026-89407",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run.\u00a0\n\n\n\nMatching cost therefore grows with the square of the input length.\u00a0\n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float).\u00a0\n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex.\u00a0\n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool.\u00a0\n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected.\u00a0\n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.11, 2.21.7, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89407"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-89407"
        },
        {
          "url": "https://getsafety.com/vulnerabilities/SFTY-20260922-89449/CVE-2026-89407"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/issues/1649"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1650"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1701"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89407"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89407"
        }
      ],
      "published": "2026-09-22T15:17:21+00:00",
      "updated": "2026-09-22T20:00:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-89425",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.21.7, 2.22.3, 2.18.11",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89425"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89425"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-89425"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1698"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89425"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89425"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-91776",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.11, 2.21.7, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-91776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-91776"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-91776"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6203"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91776"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-91777",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.7, 2.18.11, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-91777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-91777"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-91777"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6204"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6204"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91777"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ]
    },
    {
      "id": "CVE-2026-94439",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94439"
        },
        {
          "url": "https://go.dev/cl/847311"
        },
        {
          "url": "https://go.dev/issue/81744"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94439"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6613"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94439"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-94440",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94440"
        },
        {
          "url": "https://go.dev/cl/847307"
        },
        {
          "url": "https://go.dev/issue/81741"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6608"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-94448",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94448"
        },
        {
          "url": "https://go.dev/cl/839866"
        },
        {
          "url": "https://go.dev/issue/81821"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6599"
        }
      ],
      "published": "2026-10-08T23:17:05+00:00",
      "updated": "2026-10-08T23:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-97030",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97030"
        },
        {
          "url": "https://go.dev/cl/840925"
        },
        {
          "url": "https://go.dev/issue/81823"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6600"
        }
      ],
      "published": "2026-10-08T23:17:05+00:00",
      "updated": "2026-10-08T23:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-97031",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97031"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97031"
        },
        {
          "url": "https://go.dev/cl/847312"
        },
        {
          "url": "https://go.dev/issue/81855"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97031"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6607"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97031"
        }
      ],
      "published": "2026-10-08T23:17:06+00:00",
      "updated": "2026-10-08T23:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "CVE-2026-97032",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.",
      "recommendation": "Upgrade golang.org/x/net to version 0.60.0; Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97032"
        },
        {
          "url": "https://go.dev/cl/847188"
        },
        {
          "url": "https://go.dev/cl/847313"
        },
        {
          "url": "https://go.dev/issue/81867"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97032"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6617"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97032"
        }
      ],
      "published": "2026-10-08T23:17:06+00:00",
      "updated": "2026-10-08T23:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.55.0",
          "versions": [
            {
              "version": "v0.55.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.3",
          "versions": [
            {
              "version": "v1.26.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.52.0",
          "versions": [
            {
              "version": "v0.52.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.4",
          "versions": [
            {
              "version": "v1.26.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/stdlib@v1.26.3"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/net@v0.52.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/stdlib@v1.26.4"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/net@v0.55.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/stdlib@v1.26.3"
        }
      ]
    },
    {
      "id": "GHSA-hrxh-6v49-42gf",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [],
      "description": "Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:\n\n- Authorization Bypass (Fail-Open) when translating xDS RBAC policies containing `Metadata` or `RequestedServerName` fields.\n- Denial of Service (High CPU Consumption) due to an HTTP/2 Rapid Reset mitigation bypass during client-initiated stream resets.\n- Denial of Service (Server Panic) when parsing crafted xDS RBAC policies containing `NOT` rules around unsupported fields.\n\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\n#### xDS RBAC Authorization Bypass via `Metadata` & `RequestedServerName` matchers\n\n- Affected Component: xDS RBAC \n- Impact: When building policy matchers for gRPC RBAC from xDS configurations, unsupported `permission` and `principal` rules (specifically `Metadata` and `RequestedServerName`) were silently ignored and treated as no-ops.\n  - If an authorization policy relied purely on these matchers for access control, treating those rules as no-ops effectively removed the restrictions.\n- If these unsupported rules were nested inside logical `NOT` rules (`Permission_NotRule` / `Principal_NotId`) or multi-condition `OR/AND` rules, silently dropping them changed the boolean logic flow of the authorization engine.\n\nAs a result, policy evaluation decisions could fail open, allowing unauthorized clients to access protected gRPC services or resources.\n\n#### HTTP/2 Rapid Reset Mitigation Bypass / Denial of Service via Stream Aborts\n\n- Affected Component: HTTP/2 transport\n- Impact: Earlier mitigations in grpc-go for HTTP/2 Rapid Reset only applied threshold checks to items that directly resulted in control frames being written back to the wire, such as `SETTINGS` ACKs or server-initiated `RST_STREAM`s.\n\nWhen a client initiated a rapid flood of stream creation (`HEADERS`) immediately followed by stream termination `RST_STREAM`, items queued up in the control buffer without counting against the transport response frame threshold. An attacker can repeatedly trigger this flood sequence to bypass reader blocking, resulting in high CPU usage, and Denial of Service (DoS).\n\n#### Denial of Service (Panic) in xDS RBAC Engine via Unsupported Fields inside NOT Rules\n\n- Affected Component: xDS RBAC \n- Impact: The xDS RBAC policy translators recursively generate matchers for nested rules. When a `NOT` rule wrapped an unsupported or unhandled field (such as `SourcedMetadata`), the recursive step returned an empty matcher. This could result in a runtime panic when the RBAC engine attempts to authorize an incoming request.\n\nAn attacker or misconfigured/malicious xDS management server delivering an LDS/RDS update containing a `NOT` rule around an unhandled field causes the gRPC server process to crash immediately (CWE-248 / Denial of Service).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nAll three issues have been fixed in `master` and will be released in 1.82.1 shortly.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nIf upgrading grpc-go immediately is not possible, apply the following workarounds based on your deployment architecture:\n\n* For xDS RBAC Vulnerabilities & Panics: Ensure that upstream xDS management servers do not push RBAC policies containing `Metadata`, `RequestedServerName`, or `NOT` rules wrapping unsupported fields (such as `SourcedMetadata`) to grpc-go servers.\n* For HTTP/2 Rapid Reset DOS: Configure upstream reverse proxies or load balancers (such as Envoy) with strict HTTP/2 `max_concurrent_streams` limits and active rate limiting on `RST_STREAM` frequency per connection.\n\n### Severity\n\n  | Vulnerability | Qualitative Severity | Approximate CVSS v3.1 Score | Primary Impact |\n  | :--- | :--- | :--- | :--- |\n  | **xDS RBAC Authorization Bypass** | **High** | `8.2` | Unauthorized Access / Fail-Open |\n  | **HTTP/2 Rapid Reset DOS Bypass** | **High** | `7.5` | High CPU Consumption / Denial of Service |\n  | **xDS RBAC Engine Server Panic** | **Medium** | `5.9` | Process Crash / Denial of Service |",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.82.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9236"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.82.1"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf"
        }
      ],
      "published": "2026-07-21T22:03:55+00:00",
      "updated": "2026-07-21T22:03:56+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.81.1",
          "versions": [
            {
              "version": "v1.81.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.80.0",
          "versions": [
            {
              "version": "v1.80.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/google.golang.org/grpc@v1.80.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/google.golang.org/grpc@v1.81.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The affected grpc module reaches the product only through bundled Prometheus and Alertmanager binaries, used solely as an optional, disabled-by-default outbound tracing client with no gRPC server or xDS code path."
      }
    },
    {
      "id": "GHSA-mhm7-754m-9p8w",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "## Summary\n\nIn `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with both `@JsonView(RestrictedView.class)` and `@JsonTypeInfo(use=Id.NAME,\n  include=As.EXTERNAL_PROPERTY)` is populated from attacker JSON even when a more restrictive view is active.\n\n  This is a patch gap. GHSA-5hh8 (CVE-2026-54517) and GHSA-rcqc (CVE-2026-54518) descriptions cover only the main property-based path and the unwrapped-creator path respectively; the external-type-id creator path was fixed on the 3.x line via #6004 (\"Extend #5969/#5971 fixes to ... external-type-id case in regular BeanDeserializer\", commit 7dc7a17, 2026-05-22) but\n  **the fix was never backported to 2.21 or 2.18**. Users on 2.21.4 and 2.18.8 who upgraded per the published advisories remain vulnerable to the same `@JsonView` bypass technique via a different code path.\n\n## Vulnerable Code Path\n\nFile: `com/fasterxml/jackson/databind/deser/BeanDeserializer.java`\nMethod: `deserializeUsingPropertyBasedWithExternalTypeId`\n\nOn 2.21.4 (and 2.18.8), the creator-property branch (around line 1125-1158) checks `creatorProp.isInjectionOnly()` and hands off to `ext.handlePropertyValue(...)` / `buffer.assignParameter(...)` without ever consulting `visibleInView(activeView)`:\n\n ```java\n  if (creatorProp != null) {\n      // [databind#1381]: if useInput=FALSE, skip deserialization from input\n      if (creatorProp.isInjectionOnly()) { ... }\n      // NO visibleInView(activeView) CHECK HERE\n      if (!ext.handlePropertyValue(p, ctxt, propName, null)) {\n          if (buffer.assignParameter(creatorProp, ...)) { ... }\n      }\n      continue;\n  }\n```\n\nOn 3.1.4, the same branch contains the additional guard (commit 7dc7a17):\n\n ```java\n   if (creatorProp != null) {\n      // [databind#5971]: must honor active view here too\n      if ((activeView != null) && !creatorProp.visibleInView(activeView)) {\n          p.skipChildren();\n          continue;\n      }\n      ...\n  }\n```\n\nThe 2.21 and 2.18 backport PRs (#6005 and #6003) only backported the main-path fixes from #5969/#5971; the external-type-id fix from #6004 was not backported. The maintainer closed #6005\n  with \"got changes merged forward, looks like it's all covered now\", but the forward-merge did not include the ExtTypeId creator branch.\n\n  Proof of Concept\n\n  Compiles and runs against jackson-databind 2.21.4:\n \n```java\n  import com.fasterxml.jackson.annotation.*;\n  import com.fasterxml.jackson.databind.ObjectMapper;\n\n  public class JsonViewExternalTypeIdBypass {\n      public static class PublicView {}\n      public static class AdminView extends PublicView {}\n\n      public static abstract class Asset { public String name; }\n      public static class PublicAsset extends Asset {}\n      public static class AdminAsset extends Asset { public String secret; }\n\n      public static class Container {\n          @JsonTypeInfo(use = JsonTypeInfo.Id.NAME,\n                  include = JsonTypeInfo.As.EXTERNAL_PROPERTY,\n                  property = \"kind\")\n          @JsonSubTypes({\n              @JsonSubTypes.Type(value = PublicAsset.class, name = \"pub\"),\n              @JsonSubTypes.Type(value = AdminAsset.class,  name = \"admin\")\n          })\n          @JsonView(AdminView.class)\n          public Asset asset;\n\n          public String label;\n\n          @JsonCreator\n          public Container(\n                  @JsonProperty(\"label\") String label,\n                  @JsonProperty(\"asset\") @JsonView(AdminView.class) Asset asset) {\n              this.label = label;\n              this.asset = asset;\n          }\n      }\n\n      public static class Wrapper {\n          @JsonView(PublicView.class)\n          public Container data;\n      }\n\n      public static void main(String[] args) throws Exception {\n          // Admin-only \"asset\" should be blocked when reading with PublicView\n          String json = \"{\\\"data\\\":{\\\"label\\\":\\\"hello\\\",\\\"kind\\\":\\\"admin\\\",\"\n                      + \"\\\"asset\\\":{\\\"name\\\":\\\"foo\\\",\\\"secret\\\":\\\"LEAKED\\\"}}}\";\n\n          ObjectMapper om = new ObjectMapper();\n          Wrapper r = om.readerWithView(PublicView.class)\n                  .forType(Wrapper.class)\n                  .readValue(json);\n\n          System.out.println(r.data);\n          // Actual on 2.21.4:   Container{label='hello', asset=AdminAsset{name='foo', secret='LEAKED'}}\n          // Expected (secure):  Container{label='hello', asset=null}\n          if (r.data.asset != null && r.data.asset instanceof AdminAsset) {\n              System.out.println(\"[!!] BYPASS CONFIRMED \u2014 admin-only asset populated under PublicView\");\n          }\n      }\n  }\n```\n\nA control case that removes include = As.EXTERNAL_PROPERTY (forcing the normal property-based path) correctly returns asset = null, confirming the bypass is specific to the ExternalTypeId\n  code path and not a misconfiguration.\n\n### Impact\n\n  View-restricted (e.g. admin-only) creator properties can be populated from untrusted input where @JsonView is used as a write-side authorization boundary. Typical victims are Spring Boot\n  REST controllers that use @JsonView(PublicView.class) on the request body to whitelist user-settable fields \u2014 an attacker can inject the restricted creator parameter (including choosing\n  the polymorphic subtype via the sibling kind/type-id property) by combining it with a polymorphic @JsonTypeInfo(EXTERNAL_PROPERTY) annotation on the same field.\n\n- CWE-863 (Incorrect Authorization)\n- Same impact class as CVE-2026-54517 / CVE-2026-54518\n- No RCE, no DoS \u2014 this is an access-control / mass-assignment bypass\n\n### Trigger Conditions\n\nDeveloper code must combine (no opt-in user configuration required):\n\n1. Property-based @JsonCreator on the outer type\n2. A creator parameter annotated with @JsonView(RestrictedView.class)\n3. The same parameter annotated with @JsonTypeInfo(use=Id.NAME, include=As.EXTERNAL_PROPERTY, property=\"...\")",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.9, 2.21.5",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-mhm7-754m-9p8w"
        },
        {
          "url": "https://advisory.echohq.com/cve/GHSA-mhm7-754m-9p8w"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w"
        }
      ],
      "published": "2026-07-21T19:40:12+00:00",
      "updated": "2026-07-21T19:40:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "GO-2026-5932",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.",
      "advisories": [
        {
          "url": "https://go.dev/issue/44226"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5932"
        }
      ],
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.51.0",
          "versions": [
            {
              "version": "v0.51.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.49.0",
          "versions": [
            {
              "version": "v0.49.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        },
        {
          "ref": "urn:cdx:35794b9c-f156-4d8f-aa90-a7d690207dc9/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:golang/golang.org/x/crypto@v0.49.0"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:golang/golang.org/x/crypto@v0.51.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2021-46195",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-46195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2022:8415"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-46195"
        },
        {
          "url": "https://bugzilla.redhat.com/2046300"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2022-8415.html"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"
        },
        {
          "url": "https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=f10bec5ffa487ad3033ed5f38cfd0fc7d696deab"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-46195.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2022-8415.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46195"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-46195"
        }
      ],
      "published": "2022-01-14T20:15:15+00:00",
      "updated": "2026-10-08T22:17:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-10-08T19:16:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-30571",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        362
      ],
      "description": "Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-30571"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-30571"
        },
        {
          "url": "https://access.redhat.com/solutions/7033331"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/1876"
        },
        {
          "url": "https://groups.google.com/g/libarchive-announce"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30571"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-30571"
        }
      ],
      "published": "2023-05-29T20:15:09+00:00",
      "updated": "2026-06-17T05:55:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:16046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-16046.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-34459",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-34459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28254"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-34459"
        },
        {
          "url": "https://bugzilla.redhat.com/2280532"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2280532"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34459"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28254.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28254"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/720"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-34459.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28254.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34459"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7240-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-34459"
        }
      ],
      "published": "2024-05-14T15:39:11+00:00",
      "updated": "2026-06-17T07:33:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-9681",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        697
      ],
      "description": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-9681"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/06/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-9681"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g337-g667-mjvw"
        },
        {
          "url": "https://hackerone.com/reports/2764830"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9681"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7104-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-9681"
        }
      ],
      "published": "2024-11-06T08:15:03+00:00",
      "updated": "2026-06-17T08:25:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-09-15T07:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13151",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.",
      "recommendation": "Upgrade libtasn1 to version 4.16.0-10.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13151"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/08/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28253"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13151"
        },
        {
          "url": "https://bugzilla.redhat.com/2427698"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2427698"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13151"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28253.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28253"
        },
        {
          "url": "https://gitlab.com/gnutls/libtasn1"
        },
        {
          "url": "https://gitlab.com/gnutls/libtasn1/-/merge_requests/121"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13151.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-36728.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13151"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7954-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7954-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13151"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/271649"
        }
      ],
      "published": "2026-01-07T22:15:43+00:00",
      "updated": "2026-06-17T08:33:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libtasn1@4.16.0-9.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.0-9.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libtasn1@4.16.0-9.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        567
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-09-15T07:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        522,
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-28164",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        401,
        120
      ],
      "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-28164"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-28164"
        },
        {
          "url": "https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/655"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/657"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7993-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-28164"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T09:04:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5278",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
      "recommendation": "Upgrade coreutils-single to version 8.32-41.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5278"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28911"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33124"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5278"
        },
        {
          "url": "https://bugzilla.redhat.com/2368764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5278"
        },
        {
          "url": "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28911.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28911"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5278.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69964.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-coreutils/2025-05/msg00036.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-coreutils/2025-05/msg00040.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2025-5278"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8697-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5278"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/05/27/2"
        }
      ],
      "published": "2025-05-27T21:15:23+00:00",
      "updated": "2026-09-29T01:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-6170",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6170"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36734"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39304"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39317"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70596"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70639"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74360"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74362"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74363"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79119"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79120"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79121"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6170"
        },
        {
          "url": "https://bugzilla.redhat.com/2372952"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372952"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6170"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-39317.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:39317"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/941"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6170.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-39317.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6170"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7694-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6170"
        }
      ],
      "published": "2025-06-16T16:15:20+00:00",
      "updated": "2026-10-09T05:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64505",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64505"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/748"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64505"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8081-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64505"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64506",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64506"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/749"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64506"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64506"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-9232",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-9232"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/09/30/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-9232"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-76r2-c3cg-f5r9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250930.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7786-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9232"
        }
      ],
      "published": "2025-09-30T14:15:41+00:00",
      "updated": "2026-07-14T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T12:17:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-102010",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-102010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73642"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74569"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-102010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478395"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-102010"
        }
      ],
      "published": "2026-09-28T19:16:48+00:00",
      "updated": "2026-10-02T03:16:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-103111",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-103111"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-103111"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103111"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-103111"
        }
      ],
      "published": "2026-09-30T05:16:45+00:00",
      "updated": "2026-10-04T00:16:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-103242",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content \u2014 of attacker-chosen length \u2014 past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-103242"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-103242"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543866"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103242"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-103242"
        }
      ],
      "published": "2026-09-30T12:17:12+00:00",
      "updated": "2026-09-30T17:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-105712",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        61
      ],
      "description": "gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-105712"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-105712"
        },
        {
          "url": "https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-105712"
        },
        {
          "url": "https://static.dev.gnupg.org/T8159.html"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-105712"
        }
      ],
      "published": "2026-10-05T19:17:19+00:00",
      "updated": "2026-10-06T16:00:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-107161",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107161"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107161"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460420"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107161"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107161"
        }
      ],
      "published": "2026-10-07T20:17:10+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.27-22.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-107708",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107708"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107708"
        },
        {
          "url": "https://github.com/krb5/krb5"
        },
        {
          "url": "https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c#L639-L676"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7"
        },
        {
          "url": "https://github.com/krb5/krb5/pull/1510"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107708"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107708"
        },
        {
          "url": "https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac"
        }
      ],
      "published": "2026-10-08T21:17:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-107778",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107778"
        },
        {
          "url": "https://github.com/krb5/krb5"
        },
        {
          "url": "https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/lib/krb5/krb/rd_cred.c#L77-L112"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/48afa9abb89ab2176bb20624d87d010b9984fc08"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a"
        },
        {
          "url": "https://github.com/krb5/krb5/pull/1511"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107778"
        },
        {
          "url": "https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-null-pointer-dereference-via-krb5-rd-cred"
        }
      ],
      "published": "2026-10-08T21:17:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-11822",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
      "recommendation": "Upgrade sqlite-libs to version 3.34.1-11.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11822"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58936"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487258"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487269"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11822"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11824"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-58936.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:58936"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11822.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-61242-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11822"
        },
        {
          "url": "https://sqlite.org/releaselog/3_53_2.html"
        },
        {
          "url": "https://sqlite.org/src/info/061febcf41ca"
        },
        {
          "url": "https://sqlite.org/src/info/4a5ad516ea93"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8480-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11822"
        },
        {
          "url": "https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"
        }
      ],
      "published": "2026-06-09T20:16:32+00:00",
      "updated": "2026-07-23T09:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-11824",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
      "recommendation": "Upgrade sqlite-libs to version 3.34.1-11.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11824"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58936"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11824"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487258"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487269"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11822"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11824"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-58936.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:58936"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11824.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-58938.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11824"
        },
        {
          "url": "https://sqlite.org/releaselog/3_53_2.html"
        },
        {
          "url": "https://sqlite.org/src/info/061febcf41ca"
        },
        {
          "url": "https://sqlite.org/src/info/4a5ad516ea93"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8480-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11824"
        },
        {
          "url": "https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"
        }
      ],
      "published": "2026-06-09T20:16:32+00:00",
      "updated": "2026-07-23T09:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-08-31T18:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11856.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11856.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8651-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-09-15T07:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11979",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11979"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61247"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11979"
        },
        {
          "url": "https://bugzilla.redhat.com/2491354"
        },
        {
          "url": "https://bugzilla.redhat.com/2494191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491354"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494191"
        },
        {
          "url": "https://cert.pl/en/posts/2026/06/CVE-2026-11979"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11979"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6653"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-61247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:61247"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11979.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-61248-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11979"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
        }
      ],
      "published": "2026-06-29T14:16:40+00:00",
      "updated": "2026-06-30T20:22:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-08-31T18:17:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13757",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
      "recommendation": "Upgrade p11-kit to version 0.26.4-1.el9_8; Upgrade p11-kit-trust to version 0.26.4-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49667"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
        },
        {
          "url": "https://bugzilla.redhat.com/2494556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494556"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13757"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-49667.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:49667"
        },
        {
          "url": "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-13757.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8687-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
        }
      ],
      "published": "2026-06-29T19:16:40+00:00",
      "updated": "2026-09-29T01:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.26.2-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.26.2-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-14164",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
      "recommendation": "Upgrade libarchive to version 3.5.3-11.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14164"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52675"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56954"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58574"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63041"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63044"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63100"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67857"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67935"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70615"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14164"
        },
        {
          "url": "https://bugzilla.redhat.com/2493411"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493411"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14164"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-52674.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:52674"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3069"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3071"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14164.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-52675.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14164"
        }
      ],
      "published": "2026-06-30T07:16:32+00:00",
      "updated": "2026-10-08T23:17:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-14456",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14456"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14456"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14456.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14456"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260813.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14456"
        }
      ],
      "published": "2026-08-13T15:19:31+00:00",
      "updated": "2026-08-28T19:46:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-14457",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14457"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14457"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14457.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14457"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14457"
        }
      ],
      "published": "2026-08-25T13:17:49+00:00",
      "updated": "2026-09-11T21:14:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15028",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        805,
        122
      ],
      "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69553"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028"
        },
        {
          "url": "https://bugzilla.redhat.com/2497970"
        },
        {
          "url": "https://bugzilla.redhat.com/2505492"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15028"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-16517"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69553.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69553"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15028.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69553.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
        }
      ],
      "published": "2026-07-10T10:16:23+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15059",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22,
        59
      ],
      "description": "Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15059"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15059"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15059"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8626-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15059"
        }
      ],
      "published": "2026-08-10T14:17:20+00:00",
      "updated": "2026-09-01T20:54:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@252-67.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-15588",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15588"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39985"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42329"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15588"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3985"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5240"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5241"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15588.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
        }
      ],
      "published": "2026-07-20T12:17:55+00:00",
      "updated": "2026-10-06T11:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2 GDBus) whose D-Bus IPC server is never opened by any product code."
      }
    },
    {
      "id": "CVE-2026-16118",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64799"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64800"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66451"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67956"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71403"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71404"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71405"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74360"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74361"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74362"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74363"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74365"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16118"
        },
        {
          "url": "https://bugzilla.redhat.com/2501732"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501732"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-16118"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-64800.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:64800"
        },
        {
          "url": "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3992"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-16118.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-66451-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16118"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16118"
        }
      ],
      "published": "2026-07-17T20:17:16+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2/xdgmime) whose MIME-magic detection API is never invoked by any product code."
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-09-01T12:17:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-18374",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18374"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/27/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18374"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34574"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18374"
        }
      ],
      "published": "2026-08-27T20:17:03+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-18739",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18739"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510737"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18739"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18739"
        }
      ],
      "published": "2026-08-04T06:16:30+00:00",
      "updated": "2026-08-31T18:17:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.18-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-18743",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        131
      ],
      "description": "A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18743"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18743"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510809"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18743"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18743"
        }
      ],
      "published": "2026-09-01T02:16:57+00:00",
      "updated": "2026-09-08T23:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.18-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-18798",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18798"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18798"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-18798.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18798"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18798"
        }
      ],
      "published": "2026-08-25T13:17:49+00:00",
      "updated": "2026-09-23T16:07:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-18839",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77932"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2511010"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18839"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18839"
        }
      ],
      "published": "2026-08-05T21:16:57+00:00",
      "updated": "2026-10-08T15:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.18-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-18924",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18924"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-18924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-18924.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6"
        },
        {
          "url": "https://hackerone.com/reports/3916059"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18924"
        }
      ],
      "published": "2026-09-06T18:17:20+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-19542",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19542"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19542"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19542"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34506"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19542"
        }
      ],
      "published": "2026-09-14T18:17:46+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-1965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.5; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1965"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1965"
        }
      ],
      "published": "2026-03-11T11:15:59+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-19931",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        488
      ],
      "description": "A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19931"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-19931.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-19931.json"
        },
        {
          "url": "https://hackerone.com/reports/3923520"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19931"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19931"
        }
      ],
      "published": "2026-09-06T18:17:20+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.6.8-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22693",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22693"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/11/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/12/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22693"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22693"
        }
      ],
      "published": "2026-01-10T06:15:52+00:00",
      "updated": "2026-06-17T10:20:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.7.4-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-23865",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-23865"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/03/8"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9689"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23865"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9689"
        },
        {
          "url": "https://github.com/advisories/GHSA-878v-mxg6-vj8f"
        },
        {
          "url": "https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-23865.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23865"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8086-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8327-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8328-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8330-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8331-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8332-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8333-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8334-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8339-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8341-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2026-23865"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "published": "2026-03-02T17:16:32+00:00",
      "updated": "2026-06-17T10:22:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25068",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25068"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25068"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25068"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25068"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"
        }
      ],
      "published": "2026-01-29T20:16:10+00:00",
      "updated": "2026-06-17T10:24:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8706-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.11-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31790",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
      "recommendation": "Upgrade openssl-fips-provider to version 3.0.7-11.el9_8; Upgrade openssl-fips-provider-so to version 3.0.7-11.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31790"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19218"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31790"
        },
        {
          "url": "https://bugzilla.redhat.com/2451094"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451094"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31790"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19218.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19218"
        },
        {
          "url": "https://github.com/advisories/GHSA-vgxx-5xj5-q97x"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-31790.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500005.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31790"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31790"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.0.7-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl-fips-provider@3.0.7-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.0.7-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-33416",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue.",
      "recommendation": "Upgrade libpng to version 2:1.6.37-15.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33416"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28255"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33416"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451819"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33416"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33636"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28255"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/824"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33416.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33416"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33416"
        }
      ],
      "published": "2026-03-26T17:16:38+00:00",
      "updated": "2026-06-17T10:37:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-33636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        787
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.",
      "recommendation": "Upgrade libpng to version 2:1.6.37-15.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28255"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33636"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451819"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33416"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33636"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28255"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33636"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33636"
        }
      ],
      "published": "2026-03-26T17:16:41+00:00",
      "updated": "2026-06-17T10:37:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component (libpng) is only reachable via Java's ImageIO, and the sole caller found in the codebase is test-only benchmark tooling that is never shipped or exposed to attacker-controlled input."
      }
    },
    {
      "id": "CVE-2026-34180",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34180"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34180"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3c8f-qq7h-7qv6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://github.com/openssl/security/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/security/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/security/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/security/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/security/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34180.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
        }
      ],
      "published": "2026-06-09T17:17:04+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34181",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        354
      ],
      "description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key forgery.\n\nImpact Summary: An attacker impersonating a user can cause a service reading\nPKCS#12 files to accept forged certificates and private keys with a 1 in 256\nprobability.\n\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte, allowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34181"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34181"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-4jgc-cj59-f9mm"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81"
        },
        {
          "url": "https://github.com/openssl/security/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f"
        },
        {
          "url": "https://github.com/openssl/security/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610"
        },
        {
          "url": "https://github.com/openssl/security/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7"
        },
        {
          "url": "https://github.com/openssl/security/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34181.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34181"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34181"
        }
      ],
      "published": "2026-06-09T17:17:04+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34182",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        354
      ],
      "description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34182"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34182"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-f9v2-4w9p-2cwc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0"
        },
        {
          "url": "https://github.com/openssl/security/commit/03c1f4d45fb963aee7d5833390c507cd290182bc"
        },
        {
          "url": "https://github.com/openssl/security/commit/439ed7d2c0962ce964482727264668bf277c333f"
        },
        {
          "url": "https://github.com/openssl/security/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7"
        },
        {
          "url": "https://github.com/openssl/security/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac"
        },
        {
          "url": "https://github.com/openssl/security/commit/d2ca86bcd43e4f17d899f347101766b6107676e0"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34182.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34182"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34182"
        }
      ],
      "published": "2026-06-09T17:17:04+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34183",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1325
      ],
      "description": "Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34183"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-f5vx-f6jp-89j6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb"
        },
        {
          "url": "https://github.com/openssl/security/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517"
        },
        {
          "url": "https://github.com/openssl/security/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac"
        },
        {
          "url": "https://github.com/openssl/security/commit/d2e9efbe4900a373227deb136e8665401404ffac"
        },
        {
          "url": "https://github.com/openssl/security/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34183.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34183"
        }
      ],
      "published": "2026-06-09T17:17:05+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64787"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://bugzilla.redhat.com/2454589"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454589"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34743"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-64787.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:64787"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34743.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-64787-0.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.2.5-8.el9_0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34757"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34757"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/836"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/837"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34757"
        }
      ],
      "published": "2026-04-09T15:16:11+00:00",
      "updated": "2026-06-17T10:39:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-35189",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-35189"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35189"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35189"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35189"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:01:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-35191",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        440
      ],
      "description": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-35191"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35191"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35191"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35191"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:02:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-3783",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.5; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3783"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3783"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-8whr-249c-vfjp"
        },
        {
          "url": "https://hackerone.com/reports/3583983"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3783.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3783"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-40467",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 5.1.0-6.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40467"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40467.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40467"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40467"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:13:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-40468",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 5.1.0-6.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40468"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40468.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40468"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:12:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-40553",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype()\u00a0routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 5.1.0-6.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40553"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40553"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40553.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40553"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40553"
        }
      ],
      "published": "2026-07-13T13:16:37+00:00",
      "updated": "2026-07-14T01:10:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-40930",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        436
      ],
      "description": "LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40930"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/15/21"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40930"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/faf06924688b62d7c1654b5ceddedbde66ffadb4"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-c4v6-gxrq-6g2x"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40930"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40930"
        }
      ],
      "published": "2026-06-04T16:16:36+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ]
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-09-01T13:19:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@252-67.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41989",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
      "recommendation": "Upgrade libgcrypt to version 1.10.0-13.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50147"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41989"
        },
        {
          "url": "https://bugzilla.redhat.com/2461063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461063"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41989"
        },
        {
          "url": "https://dev.gnupg.org/T8211"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-50147.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:50147"
        },
        {
          "url": "https://github.com/advisories/GHSA-wrv8-79m2-qg24"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-41989.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50147-0.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41989"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8685-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.0.8-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42764",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\n\nImpact summary: NULL pointer dereference typically causes abnormal termination\nof the affected QUIC server process and a Denial of Service.\n\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\n\nBy default, the client address validation is enabled in the OpenSSL QUIC server\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42764"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42764"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-5pg7-f6xv-j6m4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91"
        },
        {
          "url": "https://github.com/openssl/security/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729"
        },
        {
          "url": "https://github.com/openssl/security/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677"
        },
        {
          "url": "https://github.com/openssl/security/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42764.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42764"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42764"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42765",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42765"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42765"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42765"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42765"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-42766",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42766"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-58mv-qqmv-gqgv"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://github.com/openssl/security/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/security/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/security/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/security/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42766.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42767",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42767"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-gxhg-7jx8-m22j"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d"
        },
        {
          "url": "https://github.com/openssl/security/commit/61a86a8cd73546c9fea916f3d304c1293e05c046"
        },
        {
          "url": "https://github.com/openssl/security/commit/665d5254083affde9982efca7c41dd01cacc8774"
        },
        {
          "url": "https://github.com/openssl/security/commit/810b722f772652ad48042bcc7ab07e3414b11d0f"
        },
        {
          "url": "https://github.com/openssl/security/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873"
        },
        {
          "url": "https://github.com/openssl/security/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42767.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42767"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42768",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        514
      ],
      "description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries \u2014 the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext \u2014 obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42768"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-5m8f-m8jv-3rp3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://github.com/openssl/security/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/security/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/security/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/security/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42768.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42768"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42769",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Issue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority (RA)\nlevel to the root Certification Authority (root CA) level.\n\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\n\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\n\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process ineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\n\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\n\nSignificant preconditions for the attack (having valid RA-level credentials)\nare the reason the issue was assigned Low severity.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42769"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-rpj2-p5pj-r33v"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/54d0989997e5fc26057009a9782c3441ce3842fb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/777b363b16fcf2153bb3ded39dc3838713667c44"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b"
        },
        {
          "url": "https://github.com/openssl/security/commit/54d0989997e5fc26057009a9782c3441ce3842fb"
        },
        {
          "url": "https://github.com/openssl/security/commit/777b363b16fcf2153bb3ded39dc3838713667c44"
        },
        {
          "url": "https://github.com/openssl/security/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c"
        },
        {
          "url": "https://github.com/openssl/security/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42769.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42769"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42769"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42770",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p\u22121)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q \u2261 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim\u2013Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42770"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3cxm-476w-ghm2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://github.com/openssl/security/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/security/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/security/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/security/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42770.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42772",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42772"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42772"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42772"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8861-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42772"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:18:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-09-01T13:19:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-31T13:18:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45445",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45445"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45445"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-v446-xwfm-x7mr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6"
        },
        {
          "url": "https://github.com/openssl/security/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451"
        },
        {
          "url": "https://github.com/openssl/security/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7"
        },
        {
          "url": "https://github.com/openssl/security/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af"
        },
        {
          "url": "https://github.com/openssl/security/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c"
        },
        {
          "url": "https://github.com/openssl/security/commit/983d54b5cce8d16147548ed1a37892d1720bbab6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-45445.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45445"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45445"
        }
      ],
      "published": "2026-06-09T17:17:18+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45446",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45446"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45446"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-7phf-qpm5-q6p3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68"
        },
        {
          "url": "https://github.com/openssl/security/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc"
        },
        {
          "url": "https://github.com/openssl/security/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3"
        },
        {
          "url": "https://github.com/openssl/security/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85"
        },
        {
          "url": "https://github.com/openssl/security/commit/daca0f48e4a69a2892a62262bad59e62a8a76598"
        },
        {
          "url": "https://github.com/openssl/security/commit/eec5e9bf0d867333b8495e456f5235d225798a68"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-45446.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45446"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45446"
        }
      ],
      "published": "2026-06-09T17:17:19+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45447",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        416,
        825
      ],
      "description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45447"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35869"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36215"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36217"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39009"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39012"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44438"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58563"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66524"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45447"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-44438.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-f684-cpcq-j565"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e"
        },
        {
          "url": "https://github.com/openssl/security/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c"
        },
        {
          "url": "https://github.com/openssl/security/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8"
        },
        {
          "url": "https://github.com/openssl/security/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54"
        },
        {
          "url": "https://github.com/openssl/security/commit/a541ae8bfe849a30cc885e8780715c0f488e496c"
        },
        {
          "url": "https://github.com/openssl/security/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-45447.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45447"
        }
      ],
      "published": "2026-06-09T17:17:19+00:00",
      "updated": "2026-09-18T13:18:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319,
        295
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-48864",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.",
      "recommendation": "Upgrade libsolv to version 0.7.24-6.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-48864"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36730"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48811"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48813"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48814"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48815"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48816"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48817"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49775"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56786"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56911"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57402"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-48864"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-39315.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:39315"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-48864.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-39315.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48864"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48864"
        }
      ],
      "published": "2026-05-26T17:16:54+00:00",
      "updated": "2026-10-09T00:17:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-49919",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49919"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49919"
        },
        {
          "url": "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49919"
        }
      ],
      "published": "2026-09-08T19:17:59+00:00",
      "updated": "2026-09-24T15:47:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-50812",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50812"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50812"
        },
        {
          "url": "https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91"
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50812"
        },
        {
          "url": "https://sqlite.org/src/info/e807d4e3798efd53"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8565-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50812"
        }
      ],
      "published": "2026-07-08T18:16:32+00:00",
      "updated": "2026-07-09T19:48:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-53613",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53613"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53613"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53613"
        }
      ],
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-5435",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
      "recommendation": "Upgrade glibc to version 2.34-274.el9_8; Upgrade glibc-common to version 2.34-274.el9_8; Upgrade glibc-minimal-langpack to version 2.34-274.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42952"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5435"
        },
        {
          "url": "https://bugzilla.redhat.com/2459854"
        },
        {
          "url": "https://bugzilla.redhat.com/2463465"
        },
        {
          "url": "https://bugzilla.redhat.com/2463539"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463465"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463539"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5928"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6238"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-42952.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:42952"
        },
        {
          "url": "https://inbox.sourceware.org/libc-alpha/cover.1777546194.git.fweimer@redhat.com/"
        },
        {
          "url": "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5435.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500297.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5435"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34033"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0011"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5435"
        }
      ],
      "published": "2026-04-28T13:19:22+00:00",
      "updated": "2026-07-14T13:19:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54369",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        59
      ],
      "description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.",
      "recommendation": "Upgrade libacl to version 2.4.0-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54369"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34351"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42736"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43420"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64805"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67144"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54369"
        },
        {
          "url": "https://bugzilla.redhat.com/2490277"
        },
        {
          "url": "https://bugzilla.redhat.com/2490279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490279"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54369"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54370"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-42736.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:42736"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54369.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43420.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54369"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54369"
        },
        {
          "url": "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-09-14T13:18:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.1-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54370",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        367
      ],
      "description": "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.",
      "recommendation": "Upgrade libacl to version 2.4.0-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54370"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42736"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54370"
        },
        {
          "url": "https://bugzilla.redhat.com/2490277"
        },
        {
          "url": "https://bugzilla.redhat.com/2490279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490279"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54369"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54370"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-42736.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:42736"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54370.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43420.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54370"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54370"
        },
        {
          "url": "https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-06-29T19:22:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.1-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54371",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59
      ],
      "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
      "recommendation": "Upgrade libattr to version 2.6.0-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56133"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59380"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60226"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54371"
        },
        {
          "url": "https://bugzilla.redhat.com/2490283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490283"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54371"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-60226.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:60226"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54371.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-60226-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8691-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/29/1"
        },
        {
          "url": "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-09-11T13:18:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.1-3.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5450",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122,
        787
      ],
      "description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
      "recommendation": "Upgrade glibc to version 2.34-272.el9_8; Upgrade glibc-common to version 2.34-272.el9_8; Upgrade glibc-minimal-langpack to version 2.34-272.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5450"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33226"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5450"
        },
        {
          "url": "https://bugzilla.redhat.com/2459853"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459853"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5450"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-33226.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:33226"
        },
        {
          "url": "https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5450.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50370.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5450"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5450#range-21286997"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0009"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5450"
        }
      ],
      "published": "2026-04-20T21:16:36+00:00",
      "updated": "2026-07-14T13:19:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54872",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54872"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54872"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54872"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54872"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-54873",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54873"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54873"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8861-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54873"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-54874",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        405
      ],
      "description": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54874"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54874"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54874.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54874"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54874"
        }
      ],
      "published": "2026-08-25T13:19:24+00:00",
      "updated": "2026-09-11T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-54875",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54875"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54875"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54875"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54875"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305,
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56109",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56109"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56109"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1"
        },
        {
          "url": "https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56109"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8538-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56109"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"
        }
      ],
      "published": "2026-06-22T18:16:48+00:00",
      "updated": "2026-07-14T22:17:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67886"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://bugzilla.redhat.com/2506691"
        },
        {
          "url": "https://bugzilla.redhat.com/2506694"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506694"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56391"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56392"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-67886.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67886"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56391.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67886.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8697-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/25/2"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-08-26T13:52:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56392",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out\u2011of\u2011bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "recommendation": "Upgrade coreutils-single to version 8.32-41.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56392"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56392"
        },
        {
          "url": "https://bugzilla.redhat.com/2506694"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506694"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56392"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-66403.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:66403"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
        },
        {
          "url": "https://github.com/advisories/GHSA-g24f-m2hx-pfgx"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56392.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67886.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-10-02T13:57:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/coreutils-single@8.32-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8720-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-09-01T12:17:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        488,
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58010",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7rp-473c-296x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58010.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-06T03:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58011",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58011"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58011"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-8xmh-8wfg-9f6j"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3917"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58011.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-06T03:17:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58012",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58012"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58012"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-vwg8-37h9-g38g"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58012.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-06T03:17:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58013",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58013"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-4x46-h598-64qr"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58013.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-06T03:17:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58014",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        193
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73866"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58014"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-h88q-m8mm-7243"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58014.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-09T04:18:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58015",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61783"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63135"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65762"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65763"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65767"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65769"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66018"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70646"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73866"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74677"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74678"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74679"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74681"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74685"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74687"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74688"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74771"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75654"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75657"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75658"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75659"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:75660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76042"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58015"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-hmpf-72wc-2r6x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58015.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-65773-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-09T04:18:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58016",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
      "recommendation": "Upgrade glib2 to version 2.68.4-19.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42090"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51175"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51176"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51177"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51181"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51182"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51184"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51185"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72394"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72399"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72502"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73909"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73959"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73960"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73961"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73962"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74459"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74460"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74461"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74462"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58016"
        },
        {
          "url": "https://bugzilla.redhat.com/2492257"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492257"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58016"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-42089.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:42089"
        },
        {
          "url": "https://github.com/advisories/GHSA-8rpw-4xx7-27w7"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3932"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58016.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-51183.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58016"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8794-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58016"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-10-02T03:16:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58055",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
      "recommendation": "Upgrade libnghttp2 to version 1.43.0-6.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54662"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58055"
        },
        {
          "url": "https://bugzilla.redhat.com/2493954"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58055"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54662.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54662"
        },
        {
          "url": "https://github.com/advisories/GHSA-xrr7-82jr-v58x"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc"
        },
        {
          "url": "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58055.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55804.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8495-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
        }
      ],
      "published": "2026-06-28T02:16:32+00:00",
      "updated": "2026-06-30T17:41:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.43.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5928",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        127
      ],
      "description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
      "recommendation": "Upgrade glibc to version 2.34-274.el9_8; Upgrade glibc-common to version 2.34-274.el9_8; Upgrade glibc-minimal-langpack to version 2.34-274.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42952"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5928"
        },
        {
          "url": "https://bugzilla.redhat.com/2459854"
        },
        {
          "url": "https://bugzilla.redhat.com/2463465"
        },
        {
          "url": "https://bugzilla.redhat.com/2463539"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463465"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463539"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5928"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6238"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-42952.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:42952"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5928.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500297.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5928"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=33998"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0010"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5928"
        }
      ],
      "published": "2026-04-20T21:16:36+00:00",
      "updated": "2026-07-14T13:19:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.8-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6238",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
      "recommendation": "Upgrade glibc to version 2.34-274.el9_8; Upgrade glibc-common to version 2.34-274.el9_8; Upgrade glibc-minimal-langpack to version 2.34-274.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6238"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42952"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6238"
        },
        {
          "url": "https://bugzilla.redhat.com/2459854"
        },
        {
          "url": "https://bugzilla.redhat.com/2463465"
        },
        {
          "url": "https://bugzilla.redhat.com/2463539"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463465"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2463539"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5928"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6238"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-42952.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:42952"
        },
        {
          "url": "https://inbox.sourceware.org/libc-alpha/cover.1777546194.git.fweimer@redhat.com/"
        },
        {
          "url": "https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6238.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500297.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6238"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34069"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0012"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6238"
        }
      ],
      "published": "2026-04-28T19:37:47+00:00",
      "updated": "2026-07-14T13:19:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        346,
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-63072",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63072"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63072.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63072"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63072"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-63073",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        134
      ],
      "description": "Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63073"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63073"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63073.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63073"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63073"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-63074",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63074"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63074"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63074.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63074"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63074"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:58+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-63075",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63075"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63075"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63075.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63075"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63075"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-63076",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63076"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63076.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63076"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63076"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-63379",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. The fix parses trailers into a temporary header list and discards them instead of merging them into req->input_headers. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63379"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63379"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/b847071141b3827900d536594ec9045eb0a4c485"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63379.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63379"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63379"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63381",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63381"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63381"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/9db091b04f569be3a700fa9860ef02f90b830af9"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63381.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63381"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63381"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63382",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63382"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63382"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63382.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63382"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63382"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63383"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63383"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63383"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63384",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63384"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63384"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63384.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63384"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63384"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63385",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63385"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63385.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63385"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63385"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63387",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        193,
        787
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63387"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63387.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63387"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8840-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63387"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-63388",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        617,
        787
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63388"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63388.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63388"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8840-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63388"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-6368",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43\u00a0can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6368"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6368"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6368"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6791"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-76777.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6368"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34090"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6368"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6653",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416,
        611
      ],
      "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6653"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61247"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6653"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"
        },
        {
          "url": "https://bugzilla.redhat.com/2491354"
        },
        {
          "url": "https://bugzilla.redhat.com/2494191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491354"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494191"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11979"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6653"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-61247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:61247"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6653.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69655.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8456-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
        }
      ],
      "published": "2026-06-22T14:17:51+00:00",
      "updated": "2026-07-14T16:00:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-67693",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "description": "An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-67693"
        },
        {
          "url": "http://gnutls.com"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-67693"
        },
        {
          "url": "https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67693"
        }
      ],
      "published": "2026-10-08T19:18:41+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.8.10-4.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.8.10-4.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnutls@3.8.10-4.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-6791",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6791"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6791"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6368"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6791"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-76777.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6791"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34091"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0013"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6791"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-72897",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-72897"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-72897"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72897"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72897"
        }
      ],
      "published": "2026-09-29T16:17:09+00:00",
      "updated": "2026-10-08T01:19:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-7383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7383"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-w853-v86g-gv7j"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://github.com/openssl/security/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/security/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/security/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/security/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/security/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-7383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-74860",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        763
      ],
      "description": "A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-74860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71641"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-74860"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-74860.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74860"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8787-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74860"
        }
      ],
      "published": "2026-09-08T12:16:58+00:00",
      "updated": "2026-10-09T02:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-75803",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        354
      ],
      "description": "Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75803"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75803"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75803"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75803"
        }
      ],
      "published": "2026-08-25T13:19:29+00:00",
      "updated": "2026-09-11T21:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-75804",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75804"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75804"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75804"
        }
      ],
      "published": "2026-09-29T16:17:10+00:00",
      "updated": "2026-10-08T01:20:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-75805",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75805"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75805"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75805"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75805"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-75806",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75806"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75806"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75806"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75806"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-77117",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77117"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77117"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34556"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77117"
        }
      ],
      "published": "2026-09-15T11:17:12+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-77696",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77696"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77696"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77696"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77696"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-78367",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        94
      ],
      "description": "A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78367"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2521857"
        },
        {
          "url": "https://github.com/rpm-software-management/rpm/issues/4314"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78367"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78367"
        }
      ],
      "published": "2026-08-24T14:17:04+00:00",
      "updated": "2026-09-04T12:17:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-80230",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80230"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80230"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-80230.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-80230.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/5267ed859d545534d0c21"
        },
        {
          "url": "https://hackerone.com/reports/3969300"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80230"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80230"
        }
      ],
      "published": "2026-09-06T18:17:22+00:00",
      "updated": "2026-09-15T07:16:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-80489",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80489"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80489"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34568"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80489"
        }
      ],
      "published": "2026-09-15T11:17:12+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-82209",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        201
      ],
      "description": "When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82209"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82209"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-82209.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-82209.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47f"
        },
        {
          "url": "https://hackerone.com/reports/3972385"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82209"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82209"
        }
      ],
      "published": "2026-09-06T18:17:22+00:00",
      "updated": "2026-09-15T07:16:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-82327",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82327"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2525602"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82327"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82327"
        }
      ],
      "published": "2026-08-28T16:18:34+00:00",
      "updated": "2026-08-28T20:20:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-8286",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.5; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8286"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-32xh-3x3c-6g6h"
        },
        {
          "url": "https://hackerone.com/reports/3718195"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8286.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-57462.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8458",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        488
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.7; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.7",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8458"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69126.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69126"
        },
        {
          "url": "https://github.com/advisories/GHSA-88c6-6jfq-mm4q"
        },
        {
          "url": "https://hackerone.com/reports/3721183"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8458.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69126.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8458"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-84782",
      "ratings": [
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.8-2.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84782"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84782"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537080"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84782"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76918"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-84782.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77396.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84782"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84782"
        }
      ],
      "published": "2026-09-29T16:17:12+00:00",
      "updated": "2026-10-08T01:20:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ]
    },
    {
      "id": "CVE-2026-84837",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84837"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84837"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478408"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84837"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84837"
        }
      ],
      "published": "2026-09-02T16:17:33+00:00",
      "updated": "2026-09-03T18:12:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86138",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86138"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86138.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86138"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86138"
        }
      ],
      "published": "2026-09-05T05:17:12+00:00",
      "updated": "2026-09-15T19:40:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86140",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86140"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86140.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86140"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8787-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86140"
        }
      ],
      "published": "2026-09-05T05:17:12+00:00",
      "updated": "2026-09-15T19:39:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86142",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86142"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86142.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71586.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86142"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86142"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:35:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86143",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        192
      ],
      "description": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86143"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86143.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86143"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86143"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:31:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86144",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        669
      ],
      "description": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86144"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86144.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86144"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86144"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:20:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86145",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        424
      ],
      "description": "PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86145"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/05/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86145"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86145"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86145"
        }
      ],
      "published": "2026-09-05T06:17:10+00:00",
      "updated": "2026-09-09T16:04:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86469",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59
      ],
      "description": "A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86469"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86469"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2473839"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86469"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86469"
        }
      ],
      "published": "2026-09-07T16:17:30+00:00",
      "updated": "2026-09-08T19:08:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-8674",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        617
      ],
      "description": "Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8674"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/17/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8674"
        },
        {
          "url": "https://joshua.hu/fuzzing-glibc-libresolv"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8674"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31026"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8674"
        }
      ],
      "published": "2026-09-17T17:16:53+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-86805",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        367
      ],
      "description": "A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86805"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86805"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86805"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34360"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86805"
        }
      ],
      "published": "2026-09-22T16:18:06+00:00",
      "updated": "2026-09-23T04:17:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-88647",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "description": "A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88647"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88647"
        },
        {
          "url": "https://gist.github.com/lkloliver/f98ec3de1a871fdfc02b70b8b9ba7642"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1802"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88647"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88647"
        }
      ],
      "published": "2026-10-08T17:17:17+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.8.10-4.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.8.10-4.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnutls@3.8.10-4.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-88648",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "description": "Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88648"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88648"
        },
        {
          "url": "https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88648"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88648"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4"
        }
      ],
      "published": "2026-10-08T19:20:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.8.10-4.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.8.10-4.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/gnutls@3.8.10-4.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-88806",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88806"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88806"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88806"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88806"
        }
      ],
      "published": "2026-09-21T14:17:22+00:00",
      "updated": "2026-09-22T19:40:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-88807",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap overflow in libXrender before 0.9.13 in\u00a0RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88807"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88807"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88807"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88807"
        }
      ],
      "published": "2026-09-21T14:17:22+00:00",
      "updated": "2026-09-22T19:40:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXrender@0.9.10-16.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.9.10-16.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-89092",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        789
      ],
      "description": "The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.\u00a0 During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.\u00a0 In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89092"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/11/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89092"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89092"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34624"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89092"
        }
      ],
      "published": "2026-09-11T02:18:35+00:00",
      "updated": "2026-09-11T18:17:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-89156",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89156"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89156"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89156"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:27:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-89157",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89157"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89157"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89157"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89157"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:25:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-89158",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89158"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89158"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89158"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89158"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:23:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-89160",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89160"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89160"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89160"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89160"
        }
      ],
      "published": "2026-09-11T04:18:04+00:00",
      "updated": "2026-09-16T19:15:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-89161",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        590
      ],
      "description": "In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89161"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89161"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/1dcd0cf42a6a7cb62cc9a7c024196733abcfda95%20%28pcre2-10.48-RC1%29"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/pull/937"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89161"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89161"
        }
      ],
      "published": "2026-09-11T04:18:04+00:00",
      "updated": "2026-09-16T19:10:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        201
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8924.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8927",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.7; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.7",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8927"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8927"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69126.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69126"
        },
        {
          "url": "https://github.com/advisories/GHSA-jr4f-4564-w3mr"
        },
        {
          "url": "https://hackerone.com/reports/3744543"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8927.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69126.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8927"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-8932",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8932"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8932"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8932.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7xm-hf59-w6rj"
        },
        {
          "url": "https://hackerone.com/reports/3733910"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8932.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8932"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-9076",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
      "recommendation": "Upgrade openssl-libs to version 1:3.5.5-4.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9076"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-25239.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-q98x-73c3-57gj"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://github.com/openssl/security/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/security/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/security/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/security/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/security/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9076.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-3.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/openssl-libs@3.5.5-3.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-90781",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        193
      ],
      "description": "alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-90781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-90781"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020"
        },
        {
          "url": "https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-90781"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"
        }
      ],
      "published": "2026-09-13T13:16:29+00:00",
      "updated": "2026-09-24T20:47:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-09-01T12:17:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9150",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9150"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/616"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9150.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9150"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9150"
        }
      ],
      "published": "2026-05-20T23:16:36+00:00",
      "updated": "2026-09-01T12:17:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libsolv@0.7.24-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-93541",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93541"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93541"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=7b6fffd13fd3914e0b39f3a4f131913da7f066e7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93541"
        }
      ],
      "published": "2026-09-24T16:17:26+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-93542",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93542"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93542"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=f499944ad595b9bd7e7571c810842244caf150aa"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93542"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93542"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-93543",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93543"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93543"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=e2089ab748828273f916bbffd4e65b506aa50fdc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93543"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93543"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-93544",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93544"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93544"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=a88a341135b79f6ed450f481e4a5d6ba502382af"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93544"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93544"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-93545",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93545"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=234ce17d95c42d75f7f7fdb2bf7a24875451bc0a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93545"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93545"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-94281",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94281"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94281"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=605f419d013153bf9e026cd100752ffbe930f3c1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94281"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94281"
        }
      ],
      "published": "2026-09-24T17:17:16+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-94283",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94283"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94283"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94283"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94283"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-94284",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94284"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94284"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94284"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94284"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-94285",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94285"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94285"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94285"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94285"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-94286",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        126
      ],
      "description": "An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94286"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94286"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94286"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94286"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.3-16.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-9547",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.5; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9547"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6"
        },
        {
          "url": "https://hackerone.com/reports/3751712"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9547.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9547"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in CP-Control-Center. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-95512",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74952"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95512"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462295"
        },
        {
          "url": "https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95512"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8881-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95512"
        }
      ],
      "published": "2026-10-02T09:16:45+00:00",
      "updated": "2026-10-06T03:17:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-95519",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95519"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2470977"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95519"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95519"
        }
      ],
      "published": "2026-09-24T14:18:20+00:00",
      "updated": "2026-09-25T13:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-95520",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95520"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537809"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95520"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95520"
        }
      ],
      "published": "2026-09-29T12:17:12+00:00",
      "updated": "2026-09-29T21:29:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-95521",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95521"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95521"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95521"
        }
      ],
      "published": "2026-09-24T14:18:20+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-95619",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95619"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58503"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67275"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95619"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537811"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2026-September/732381.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95619"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95619"
        }
      ],
      "published": "2026-09-22T13:17:13+00:00",
      "updated": "2026-09-22T19:37:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-95818",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95818"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34360"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95818"
        }
      ],
      "published": "2026-09-22T17:17:32+00:00",
      "updated": "2026-09-22T19:56:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-96674",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-96674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-96674"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/pull/527"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96674"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96674"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file"
        }
      ],
      "published": "2026-09-23T16:16:50+00:00",
      "updated": "2026-09-24T21:08:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-96675",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-96675"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-96675"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/pull/527"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96675"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96675"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi"
        }
      ],
      "published": "2026-09-23T16:16:50+00:00",
      "updated": "2026-09-24T21:08:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-97399",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        126
      ],
      "description": "The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/28/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97399"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97399"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34683"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97399"
        }
      ],
      "published": "2026-09-28T16:17:18+00:00",
      "updated": "2026-09-29T21:36:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-270.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:44749c59-c197-4edd-bfd0-057c42263d0e/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9cef40f5-82e6-4408-b20a-1069fabe9e43/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-common@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2cd6ba2b-bfad-4ec0-b84e-6ab7a936040b/1#pkg:rpm/redhat/glibc@2.34-270.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    }
  ]
}